Gone Phishing
ID: 32dbf639-cd21-5d27-948f-5f3eb61bab50
STIX ID: report--32dbf639-cd21-5d27-948f-5f3eb61bab50
Feed Name: IntelInsights (Substack)
Threat researchers report active Rhadamanthys infostealer activity leveraging phishing (malicious PDFs and password-protected ZIPs with LNK→PowerShell→in-memory payload) and highlight the malware’s evolving capabilities (v0.7.0 with AI OCR to extract crypto wallet seed phrases). Using Censys pivots across HTTP banners, TLS certificate hash, JARM fingerprinting, OpenSSH 8.0, and Windows Server 2012 indicators, the report enumerates additional related infrastructure and publishes multiple IP addresses as potential IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
