The Rhadamanthys information stealer now includes advanced features, such as artificial intelligence (AI) for optical character recognition (OCR), through its newly implemented "Seed Phrase Image Recognition" capability. This allows the malware to extract cryptocurrency wallet seed phrases from images, significantly increasing its threat level for crypto users, as noted in an analysis by Recorded Future’s Insikt Group. First discovered in September 2022, Rhadamanthys has become a prominent malware-as-a-service (MaaS) tool, continuing to operate despite bans from underground forums. Its developer, known as "kingcrete," markets new versions through platforms like Telegram and Jabber. The malware is offered on a subscription basis—$250 per month or $550 for three months—enabling customers to gather sensitive data, including credentials and cryptocurrency wallet information, while employing techniques to evade detection. Version 0.7.0, released in June 2024, features a complete overhaul for improved stability, incorporating 30 wallet-cracking algorithms and enhanced PDF recognition for seed phrase extraction. It also allows the execution of Microsoft Software Installer (MSI) files to avoid detection and includes settings to prevent re-execution within a configurable timeframe. In addition, Rhadamanthys includes a plugin system that can enhance its functionalities, allowing for keylogger and cryptocurrency clipper capabilities. Organizations are urged to enhance security measures to protect against this evolving and formidable threat.
A newly discovered ransomware campaign is targeting Windows systems across South America by impersonating the well-known Akira ransomware group. The attackers mimic Akira’s brand...
A large-scale phishing campaign has been identified leveraging RFQ (Request for Quotation) themed emails to distribute credential-stealing malware. Attackers disguise malicious HTM...
Two critical vulnerabilities in Progress ShareFile have been identified that can be chained to achieve pre-authentication remote code execution (RCE). Discovered by watchTowr resea...