Rhadamanthys first appeared in 2022 as a “modular stealer” delivered using the Malware-as-a-Service, but its latest campaign shows how quickly it is evolving using the ClickFix technique.
See also: Hackers use ClickFix technique to deploy Trojans

At the heart of this new Rhadamanthys campaign is a tricked-out CAPTCHA page called ClickFix, which prompts victims to "verify" their session by pasting a PowerShell command.
Once executed, the command silently connects to hxxps://ypp-studio[.]com/update.txt, disables execution policy restrictions, and downloads the next stage of the malware directly into memory—remaining completely fileless until the final stage.
Dark Atlas analysts noted that the deceptive pages are hosted on newly registered domains with typosquats, which often mimic YouTube Partner Studio or similar SaaS platforms, while the malware infrastructure has been moved from the previous host 77.239.96.51/rh_0.9.0.exe to the new address 62.60.226.74/PTRFHDGS.msi.
This subtle change breaks the static IoCs used by many security tools, while preserving the stealer's propagation chain.
See also: Hackers are now testing ClickFix attacks against Linux
Campaign telemetry data shows a significant increase in infections in small and medium-sized businesses during June and early July 2025, with browsing cookies and cloud credentials appearing in dark web marketplaces within hours of infection.

What makes ClickFix particularly dangerous is the level of social engineering. The CAPTCHA offers a false sense of legitimacy, accurately instructing the victim to press Win + R, paste the command, and press Enter.
This simple action bypasses traditional email gateway and avoids macros, which are often the target of security teams. By the time the user sees the reassuring pop-up message “Verification completed!”, Rhadamanthys has already unpacked in the background and started transferring data to the C2 server at 193.109.85.136.
See also: ClickFix: COLDRIVER hackers distribute LOSTKEYS malware
A key takeaway from the Rhadamanthys case and the ClickFix is the increasing sophistication and effectiveness of modern social engineering techniques, especially when combined with fileless attacks. The speed with which stolen credentials end up on the dark web also suggests automation and connectivity with larger data-selling networks—making a single breach a much broader risk to businesses and customers.
Source: cybersecuritynews
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
