HomeSecurityRhadamanthys Infostealer leverages the ClickFix technique

Rhadamanthys Infostealer leverages the ClickFix technique

Rhadamanthys first appeared in 2022 as a “modular stealer” delivered using the Malware-as-a-Service, but its latest campaign shows how quickly it is evolving using the ClickFix technique.

See also: Hackers use ClickFix technique to deploy Trojans

Rhadamanthys ClickFix

At the heart of this new Rhadamanthys campaign is a tricked-out CAPTCHA page called ClickFix, which prompts victims to "verify" their session by pasting a PowerShell command.

Once executed, the command silently connects to hxxps://ypp-studio[.]com/update.txt, disables execution policy restrictions, and downloads the next stage of the malware directly into memory—remaining completely fileless until the final stage.

Dark Atlas analysts noted that the deceptive pages are hosted on newly registered domains with typosquats, which often mimic YouTube Partner Studio or similar SaaS platforms, while the malware infrastructure has been moved from the previous host 77.239.96.51/rh_0.9.0.exe to the new address 62.60.226.74/PTRFHDGS.msi.

This subtle change breaks the static IoCs used by many security tools, while preserving the stealer's propagation chain.

See also: Hackers are now testing ClickFix attacks against Linux

Campaign telemetry data shows a significant increase in infections in small and medium-sized businesses during June and early July 2025, with browsing cookies and cloud credentials appearing in dark web marketplaces within hours of infection.

Rhadamanthys Infostealer leverages the ClickFix technique
Rhadamanthys Infostealer leverages the ClickFix technique

What makes ClickFix particularly dangerous is the level of social engineering. The CAPTCHA offers a false sense of legitimacy, accurately instructing the victim to press Win + R, paste the command, and press Enter.

This simple action bypasses traditional email gateway and avoids macros, which are often the target of security teams. By the time the user sees the reassuring pop-up message “Verification completed!”, Rhadamanthys has already unpacked in the background and started transferring data to the C2 server at 193.109.85.136.

See also: ClickFix: COLDRIVER hackers distribute LOSTKEYS malware

A key takeaway from the Rhadamanthys case and the ClickFix is the increasing sophistication and effectiveness of modern social engineering techniques, especially when combined with fileless attacks. The speed with which stolen credentials end up on the dark web also suggests automation and connectivity with larger data-selling networks—making a single breach a much broader risk to businesses and customers.

Source: cybersecuritynews

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS