logo

Tech Analysis of Rhadamanthys Obfuscation Techniques

ID: 41dcf7c8-5a0f-57a2-ae1c-e52e8603d7f4

STIX ID: report--41dcf7c8-5a0f-57a2-ae1c-e52e8603d7f4

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report presents a technical analysis of the Rhadamanthys malware family, detailing its multi-stage loader (initialization, decompression, loader), VM-based obfuscation, encryption/compression schemes, an embedded virtual file system with helper modules, and a main module containing components for credential exfiltration (including a KeePass-focused module and Lua extraction scripts), code injection, and runtime execution of PowerShell and other payloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.