New MaaS InfoStealer Malware Campaign Targeting Oil & Gas Sector
ID: 36232487-a974-54b7-bab5-1ba8d08988d8
STIX ID: report--36232487-a974-54b7-bab5-1ba8d08988d8
Feed Name: Cofense Blog
Cofense Intelligence reports an active, high-volume phishing campaign targeting the Oil and Gas sector that delivers the Rhadamanthys Stealer via open redirects and an interactive PDF hosted on a newly registered domain (docptypefinder.info). The chain redirects users through legitimate services to a GitHub-hosted ZIP containing the stealer executable; once run, the malware exfiltrates credentials, documents, and cryptocurrency wallets. The report notes a recent major update to the stealer (v5.0), discusses evasion techniques used to bypass secure email gateways, and provides IOCs for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
