logo

One year later, Rhadamanthys is still dropped via malvertising

ID: 6d22bc58-0826-573f-9619-5185b07c440b

STIX ID: report--6d22bc58-0826-573f-9619-5185b07c440b

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2024-02-28

Date Updated: 2026-04-28

...
...

This report details an ongoing malvertising campaign impersonating legitimate software (e.g., Notion) to deliver droppers that retrieve the Rhadamanthys infostealer and other malware; it includes traffic and landing-page analysis, dropper behavior, IOCs (hashes, IPs, domains, download URLs), observed targeting of business users, and recommended mitigations such as DNS filtering and EDR protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.