logo

Copyright Phishing Lures Leading to Rhadamanthys Stealer Now Targeting Europe

ID: b6188321-804f-559f-8c49-0dec77c1c464

STIX ID: report--b6188321-804f-559f-8c49-0dec77c1c464

Feed Name: Cybereason Blog

Threat Score
75/100

Date Published: 2025-05-21

Date Updated: 2026-04-27

Author: Cybereason Security Services Team

...
...

Cybereason observed a Europe-focused phishing campaign (since April 2025) using copyright-infringement lures and redirect links to host archives on Mediafire; these archives contain a legitimate PDF reader and a malicious msimg32.dll that is executed via DLL side-loading to deploy the Rhadamanthys infostealer. The report provides a technical analysis of the multi-stage loader (TLS callbacks, multi-stage shellcode, Heaven's Gate/indirect syscalls), persistence via autorun registry keys, indicators of compromise (IPs, domains, hashes, filenames), targeted sectors/countries, detection artifacts, and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.