logo

Rhadamanthys Infostealer Leveraging ClickFix Technique to Steal Login Credentials

ID: 8efdd47b-d1f0-54a3-a335-c5f84e26f787

STIX ID: report--8efdd47b-d1f0-54a3-a335-c5f84e26f787

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-07-10

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A recent campaign by the Rhadamanthys infostealer (ClickFix) uses fake CAPTCHA/verification pages hosted on typosquatted portals to trick users into pasting a PowerShell command from the clipboard; the command loads a fileless stage from https://ypp-studio.com/update.txt then downloads an MSI (PTRFHDGS.msi) which drops rh_0.9.0.exe. The malware employs execution-policy bypass, LOLBins (msiexec), process injection into WerFault.exe, sandbox/debug checks, and hard-coded C2 IPs (e.g., 193.109.85.136) to exfiltrate browser databases, crypto wallets and credentials—with an observed spike in SME infections and stolen data appearing on dark-web markets in June–July 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.