Developers of the Rhadamanthys information-stealing malware have recently launched two significant versions, introducing enhancements and improvements, including new stealing capabilities and enhanced evasion tactics. Initially emerging in August 2022, Rhadamanthys is a C++ information stealer known for targeting email, FTP, and online banking service credentials. It operates on a subscription model, distributed through various channels like malvertising, torrent downloads, emails, and YouTube videos. Check Point researchers analyzed Rhadamanthys versions 0.5.0 and 0.5.1, highlighting substantial changes. Version 0.5.0 introduced a plugin system, allowing customization for specific distribution needs, reflecting a shift toward a more modular and customizable framework. Notable features included the 'Data Spy' plugin for monitoring RDP logins, improved stub construction, and fixes targeting cryptocurrency wallets. Additional enhancements encompassed browser data stealing, user panel search settings, and options to modify Telegram notifications. The XS1 loader, part of the Rhadamanthys framework, exhibited anti-analysis checks, an embedded configuration, and modules for the next stage. Version 0.5.1 added a Clipper plugin diverting crypto payments, Telegram options for wallet crack exfiltration, recovery of deleted Google Account cookies, and evasion of Windows Defender, including cloud protection. Rhadamanthys' active development and rapid introduction of features make it a formidable tool for cybercriminals. The evolving nature of Rhadamanthys suggests that threat actors may increasingly adopt it as its capabilities continue to expand. The dynamic development and feature-rich updates underscore the importance of ongoing vigilance and countermeasures to combat evolving cyber threats.
Security researchers have identified a new variant of the SparkCat malware circulating on both the Apple App Store and Google Play Store, more than a year after its initial discove...
The European Union’s cybersecurity agency, CERT-EU, has attributed a significant cloud breach involving the European Commission to the TeamPCP threat group. The attack targeted t...
Microsoft has rolled out automatic updates for unmanaged Windows 11 24H2 Home and Pro edition devices to Windows 11 25H2, also known as the Windows 11 2025 Update. This transition ...