Recently Updated Rhadamanthys Stealer Delivered in Federal Bureau of Transportation Campaign
ID: 38d3bbab-e35a-5adc-9beb-295a97c8c0ab
STIX ID: report--38d3bbab-e35a-5adc-9beb-295a97c8c0ab
Feed Name: Cofense Blog
Threat Score
Cofense Intelligence identified a targeted phishing campaign aimed at the Oil & Gas sector that uses open redirects on legitimate Google domains, URL shorteners, and a spoofed Federal Bureau of Transportation PDF lure (vehicle-incident theme) to deliver a ZIP containing an executable that deploys Rhadamanthys Stealer—a C++ MaaS infostealer that exfiltrates credentials and cryptocurrency wallets to a C2.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
