logo

New MaaS InfoStealer Malware Campaign Targeting Oil & Gas Sector

ID: 36232487-a974-54b7-bab5-1ba8d08988d8

STIX ID: report--36232487-a974-54b7-bab5-1ba8d08988d8

Feed Name: Cofense Blog

Threat Score
75/100

Date Published: 2024-02-22

Date Updated: 2026-04-27

Author: Cofense

...
...

Cofense Intelligence reports an active, high-volume phishing campaign targeting the Oil and Gas sector that delivers the Rhadamanthys Stealer via open redirects and an interactive PDF hosted on a newly registered domain (docptypefinder.info). The chain redirects users through legitimate services to a GitHub-hosted ZIP containing the stealer executable; once run, the malware exfiltrates credentials, documents, and cryptocurrency wallets. The report notes a recent major update to the stealer (v5.0), discusses evasion techniques used to bypass secure email gateways, and provides IOCs for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.