logo

Don't open that 'copyright infringement' email attachment – it's an infostealer

ID: 40da8dc5-4f67-5685-b1d7-896304a2680a

STIX ID: report--40da8dc5-4f67-5685-b1d7-896304a2680a

Feed Name: The Register (Security)

Threat Score
72/100

Date Published: 2024-11-07

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Rhadamanthys 0.7 is being spread via a global phishing campaign that impersonates legal copyright complaints; recipients receive password-protected ZIPs which, when extracted, present a decoy PDF and an executable that side-loads a DLL containing the infostealer. The variant leverages AI-driven OCR to hunt for cryptocurrency seed phrases and other sensitive data, may deploy MSI files to evade defenses, and targets organizations across multiple countries, indicating an active, financially motivated threat with provided technical writeups and IoCs from multiple security researchers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.