Fake Copyright Infringement Emails Spread Rhadamanthys
ID: b685c8a9-16d6-5e8b-a3d8-146601b18768
STIX ID: report--b685c8a9-16d6-5e8b-a3d8-146601b18768
Feed Name: Dark Reading
Check Point tracked a global spear-phishing campaign, CopyR(ight)hadamantys, that uses bespoke copyright-violation lures to trick recipients into downloading archives which deploy the Rhadamanthys infostealer via a malicious DLL. The stealer is modular and sophisticated — including an OCR component trained on Bitcoin wallet protection phrases and an evasion tactic that appends a large useless overlay to change file hashes and possibly evade antivirus — and the campaign has targeted hundreds of companies across multiple regions, with ties noted to known threat groups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
