logo

Rhadamanthys infostealer disrupted as cybercriminals lose server access

ID: 1cb47496-e991-5e7a-af66-7c8b56bceb36

STIX ID: report--1cb47496-e991-5e7a-af66-7c8b56bceb36

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-11-12

Date Updated: 2026-07-18

Author: Lawrence Abrams

...
...

The Rhadamanthys infostealer operation, a subscription-based malware-as-a-service that steals credentials and cookies, has been disrupted with customers reporting loss of web-panel and SSH access—potentially due to law enforcement (German authorities/Operation Endgame). Researchers and forum posts describe EU-hosted panels showing German IP access before customers lost control; Tor sites are offline and the developer suspects a police action, though attribution is not confirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.