CopyRh(ight)adamantys Campaign: Rhadamantys Exploits Intellectual Property Infringement Baits
ID: 40fca800-ba74-50e9-8104-848428405e8e
STIX ID: report--40fca800-ba74-50e9-8104-848428405e8e
Feed Name: Check Point Research
Check Point Research describes a widespread phishing campaign (CopyRh(ight)adamantys) active since July 2024 that uses copyright-themed spear-phishing to deliver Rhadamanthys stealer v0.7 via DLL sideloading and password-protected archives; the report includes a detailed infection chain, analysis of a new OCR module aimed at extracting BIP39 wallet phrases, numerous IOCs (C2 IPs and file hashes), and attributes the activity to financially motivated cybercriminals rather than a nation-state.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
