Rhadamanthys Infostealer Leveraging ClickFix Technique to Steal Login Credentials
ID: 8efdd47b-d1f0-54a3-a335-c5f84e26f787
STIX ID: report--8efdd47b-d1f0-54a3-a335-c5f84e26f787
Feed Name: cybersecurityNews.com
A recent campaign by the Rhadamanthys infostealer (ClickFix) uses fake CAPTCHA/verification pages hosted on typosquatted portals to trick users into pasting a PowerShell command from the clipboard; the command loads a fileless stage from https://ypp-studio.com/update.txt then downloads an MSI (PTRFHDGS.msi) which drops rh_0.9.0.exe. The malware employs execution-policy bypass, LOLBins (msiexec), process injection into WerFault.exe, sandbox/debug checks, and hard-coded C2 IPs (e.g., 193.109.85.136) to exfiltrate browser databases, crypto wallets and credentials—with an observed spike in SME infections and stolen data appearing on dark-web markets in June–July 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
