RhadaManthys Stealer Spreading Via Google Ads: Key Insights
ID: 8fc60ec0-de17-5bda-861f-de07cb412e66
STIX ID: report--8fc60ec0-de17-5bda-861f-de07cb412e66
Feed Name: Cyble Blog
Cyble Research & Intelligence Labs describes an active Rhadamanthys info-stealer campaign that delivers a PyInstaller-based loader via spam email attachments and Google Ads–driven phishing sites; the malware performs anti-VM checks, injects a PE shellcode, drops and executes a DLL via rundll32, harvests system/browser credentials and crypto-wallet data, and exfiltrates to an active C2. The report includes MITRE ATT&CK mappings and multiple IOCs (SHA256 hashes and phishing domains) to support detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
