Description

The Rhadamanthys information stealer now includes advanced features, such as artificial intelligence (AI) for optical character recognition (OCR), through its newly implemented "Seed Phrase Image Recognition" capability. This allows the malware to extract cryptocurrency wallet seed phrases from images, significantly increasing its threat level for crypto users, as noted in an analysis by Recorded Future’s Insikt Group. First discovered in September 2022, Rhadamanthys has become a prominent malware-as-a-service (MaaS) tool, continuing to operate despite bans from underground forums. Its developer, known as "kingcrete," markets new versions through platforms like Telegram and Jabber. The malware is offered on a subscription basis—$250 per month or $550 for three months—enabling customers to gather sensitive data, including credentials and cryptocurrency wallet information, while employing techniques to evade detection. Version 0.7.0, released in June 2024, features a complete overhaul for improved stability, incorporating 30 wallet-cracking algorithms and enhanced PDF recognition for seed phrase extraction. It also allows the execution of Microsoft Software Installer (MSI) files to avoid detection and includes settings to prevent re-execution within a configurable timeframe. In addition, Rhadamanthys includes a plugin system that can enhance its functionalities, allowing for keylogger and cryptocurrency clipper capabilities. Organizations are urged to enhance security measures to protect against this evolving and formidable threat.