Distribution of Rhadamanthys Malware Disguised as a Game Developed with Ren’Py
ID: 313d9b5b-0d08-58d6-974d-2fc83ac07576
STIX ID: report--313d9b5b-0d08-58d6-974d-2fc83ac07576
Feed Name: ASEC
AhnLab ASEC reports that the Rhadamanthys infostealer is being distributed by embedding malicious Python scripts inside Ren'Py game packages delivered via ZIP links (e.g., MediaFire). The attack chain uses a legitimate installer to extract a compiled archive.rpa containing a modified script.rpy that imports a malicious python-package (__init__.py), performs environment checks, decodes a .key configuration, drops and runs a benign-looking executable which loads a DLL and injects the Rhadamanthys payload into a child .NET process; the report includes detection names, MD5 hashes, and C2 URLs as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
