logo

RhadaManthys Stealer Spreading Via Google Ads: Key Insights

ID: 8fc60ec0-de17-5bda-861f-de07cb412e66

STIX ID: report--8fc60ec0-de17-5bda-861f-de07cb412e66

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2025-05-21

Date Updated: 2026-07-16

...
...

Cyble Research & Intelligence Labs describes an active Rhadamanthys info-stealer campaign that delivers a PyInstaller-based loader via spam email attachments and Google Ads–driven phishing sites; the malware performs anti-VM checks, injects a PE shellcode, drops and executes a DLL via rundll32, harvests system/browser credentials and crypto-wallet data, and exfiltrates to an active C2. The report includes MITRE ATT&CK mappings and multiple IOCs (SHA256 hashes and phishing domains) to support detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.