One year later, Rhadamanthys is still dropped via malvertising
ID: 6d22bc58-0826-573f-9619-5185b07c440b
STIX ID: report--6d22bc58-0826-573f-9619-5185b07c440b
Feed Name: Malwarebytes Blog
Threat Score
This report details an ongoing malvertising campaign impersonating legitimate software (e.g., Notion) to deliver droppers that retrieve the Rhadamanthys infostealer and other malware; it includes traffic and landing-page analysis, dropper behavior, IOCs (hashes, IPs, domains, download URLs), observed targeting of business users, and recommended mitigations such as DNS filtering and EDR protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
