logo

Rhadamanthys Infostealer Being Distributed Through MSC Extension

ID: 0d4539f1-a25c-5678-844c-b9f535d3d265

STIX ID: report--0d4539f1-a25c-5678-844c-b9f535d3d265

Feed Name: ASEC

Threat Score
75/100

Date Published: 2025-02-17

Date Updated: 2026-04-26

Author: ATCP

...
...

AhnLab ASEC warns of active distribution of the Rhadamanthys infostealer via malicious .msc files that either exploit apds.dll (CVE-2024-43572) or leverage MMC Console Taskpad to run PowerShell downloaders; the malware drops an EXE disguised as eRSg.mp3, and the report provides technical analysis plus MD5 hashes and URLs as IOCs. The CVE-based attack is less effective after patches, but Console Taskpad abuse allows continued successful delivery, so users should avoid opening .msc files from untrusted sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.