logo

Gone Phishing

ID: 32dbf639-cd21-5d27-948f-5f3eb61bab50

STIX ID: report--32dbf639-cd21-5d27-948f-5f3eb61bab50

Feed Name: IntelInsights (Substack)

Threat Score
70/100

Date Published: 2024-12-01

Date Updated: 2026-04-19

Author: Vasilis Orlof

...
...

Threat researchers report active Rhadamanthys infostealer activity leveraging phishing (malicious PDFs and password-protected ZIPs with LNK→PowerShell→in-memory payload) and highlight the malware’s evolving capabilities (v0.7.0 with AI OCR to extract crypto wallet seed phrases). Using Censys pivots across HTTP banners, TLS certificate hash, JARM fingerprinting, OpenSSH 8.0, and Windows Server 2012 indicators, the report enumerates additional related infrastructure and publishes multiple IP addresses as potential IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.