Rhadamanthys Infostealer Being Distributed Through MSC Extension
ID: 0d4539f1-a25c-5678-844c-b9f535d3d265
STIX ID: report--0d4539f1-a25c-5678-844c-b9f535d3d265
Feed Name: ASEC
AhnLab ASEC warns of active distribution of the Rhadamanthys infostealer via malicious .msc files that either exploit apds.dll (CVE-2024-43572) or leverage MMC Console Taskpad to run PowerShell downloaders; the malware drops an EXE disguised as eRSg.mp3, and the report provides technical analysis plus MD5 hashes and URLs as IOCs. The CVE-based attack is less effective after patches, but Console Taskpad abuse allows continued successful delivery, so users should avoid opening .msc files from untrusted sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
