Tech Analysis of Rhadamanthys Obfuscation Techniques
ID: 41dcf7c8-5a0f-57a2-ae1c-e52e8603d7f4
STIX ID: report--41dcf7c8-5a0f-57a2-ae1c-e52e8603d7f4
Feed Name: Zscaler Security Research Blog
Threat Score
This report presents a technical analysis of the Rhadamanthys malware family, detailing its multi-stage loader (initialization, decompression, loader), VM-based obfuscation, encryption/compression schemes, an embedded virtual file system with helper modules, and a main module containing components for credential exfiltration (including a KeePass-focused module and Lua extraction scripts), code injection, and runtime execution of PowerShell and other payloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
