The Rhadamanthys information stealer now includes advanced features, such as artificial intelligence (AI) for optical character recognition (OCR), through its newly implemented "Seed Phrase Image Recognition" capability. This allows the malware to extract cryptocurrency wallet seed phrases from images, significantly increasing its threat level for crypto users, as noted in an analysis by Recorded Future’s Insikt Group. First discovered in September 2022, Rhadamanthys has become a prominent malware-as-a-service (MaaS) tool, continuing to operate despite bans from underground forums. Its developer, known as "kingcrete," markets new versions through platforms like Telegram and Jabber. The malware is offered on a subscription basis—$250 per month or $550 for three months—enabling customers to gather sensitive data, including credentials and cryptocurrency wallet information, while employing techniques to evade detection. Version 0.7.0, released in June 2024, features a complete overhaul for improved stability, incorporating 30 wallet-cracking algorithms and enhanced PDF recognition for seed phrase extraction. It also allows the execution of Microsoft Software Installer (MSI) files to avoid detection and includes settings to prevent re-execution within a configurable timeframe. In addition, Rhadamanthys includes a plugin system that can enhance its functionalities, allowing for keylogger and cryptocurrency clipper capabilities. Organizations are urged to enhance security measures to protect against this evolving and formidable threat.
A threat actor identified as UAC-0184 has been linked to targeted cyber espionage campaigns against Ukrainian military and government organizations. The campaign leverages phishing...
Cybersecurity researchers have identified a widespread malware campaign abusing fake Google Chrome update prompts to infect users with malicious payloads. The attack leverages comp...
Microsoft has introduced a significant security enhancement in its Edge browser after security researchers disclosed that the browser was automatically loading all saved passwords ...