One of the most notorious malware-as-a-service (MaaS) appears to have gone down. Rhadamanthys, a well-known malware used by cybercriminals to steal credentials and sensitive data, appears to have suffered a major outage, with many of its “customers” reporting losing access to their servers.

What is Rhadamanthus?
Rhadamanthys operated as an information -stealing platform , allowing its users to extract passwords , cookies, and login data from browsers, email applications, and other clients. The malware was widely distributed through deceptive campaigns , such as fake cracks for popular software, YouTube videos promising “free activations,” or malicious ads in search engines.
See also: GootLoader: New hiding technique on WordPress websites
Its business model was simple but dangerous: cybercriminals paid a subscription fee to use the tool, receiving technical support and access to an online dashboard where stolen victims’ data was centralized. In other words, Rhadamanthys operated like a legitimate SaaS service — just for illegal use.
The sudden shutdown
On Tuesday morning, several Rhadamanthys “customers” reported on hacking forums that they could no longer connect to their servers via SSH. As they noted, the login method had suddenly changed: instead of the familiar root passwords, the systems were now asking for authentication certificates, suggesting third-party interference.

One of the users warned: “If your password doesn’t work, check if the login method has been changed to a certificate. If so, reinstall your server immediately and delete all traces — the German police are in action.”
Other subscribers confirmed similar incidents, reporting that root passwords were deleted and that access was only allowed via certificates. One of them said that he was forced to immediately delete everything and deactivate the server, as he found traces of external access.
See also: Android Trojan 'Fantasy Hub' turns Telegram into a hub for hackers
Suspicious connections from German IPs
Shortly afterwards, a message from the Rhadamanthys developer circulated on the same forums, suggesting that German enforcement law was behind the outage. The servers hosting the online panels had IP addresses within the European Union, and according to reports, connections were detected from German networks shortly before access was lost.
Researcher g0njxa , who has been closely monitoring the situation, told BleepingComputer that even Rhadamanthys' Tor (onion) sites are down . While they don't display an official police seizure banner , the fact that they remain unavailable supports the idea that this is an law enforcement operation ongoing
Possible connection to Operation Endgame
The cyber community is linking the case to Operation Endgame, an international initiative launched in 2024 that targets criminal malware infrastructures. Endgame has already managed to disrupt networks associated with Trickbot, IcedID, DanaBot, SmokeLoader, Bumblebee, and other malware-as-a-service ecosystems.
See also: Abuse of RMM tools to distribute Medusa & DragonForce ransomware

The Operation Endgame website is reportedly currently displaying a countdown timer to an announcement on Thursday, which has sparked rumors that Rhadamanthys is the campaign's next big "victim.
The end of a dark "service"?
If the authorities' involvement is confirmed, the "lockdown" of Rhadamanthys marks another blow to the criminal markets of the dark web, but also a victory for international cooperation against cybercrime. At the same time, it reminds us that the malware economy has now transformed into an industry with organized networks, corporate structure and clientele.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The Rhadamanthys case may prove to be a turning point in the fight against malware as a service. For now, cybercriminals are looking for alternative platforms, while authorities appear to have only just begun their counterattack.
Source: www.bleepingcomputer.com
