logo

Rhadamanthys Stealer Analysis for Detection Opportunities

ID: f2236a4d-9162-538f-9342-d78d8721c69b

STIX ID: report--f2236a4d-9162-538f-9342-d78d8721c69b

Feed Name: Binary Defense Blog

Threat Score
70/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

Binary Defense ARC Labs analyzes a Rhadamanthys Stealer campaign that uses phishing and SEO-poisoned downloads to deliver an obfuscated payload (Almost.cmd → internet.pif → InnoWave.pif), performs discovery with tasklist/findstr, merges files to evade detection, and injects into legitimate processes (OpenWith.exe) to steal browser credentials and screenshots; observed C2 communication to 144.76.133.166:8034 and use of processes like wmpnscfg.exe and dllhost.exe for exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.