logo

Rhadamanthys Malware: Swiss Army Knife of Information Stealers Emerges

ID: 1c8c95e1-7a2b-5ecb-adca-9efd56d53cdb

STIX ID: report--1c8c95e1-7a2b-5ecb-adca-9efd56d53cdb

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2023-12-18

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

The report details active malware activity: Rhadamanthys, an information stealer sold as malware-as-a-service, is rapidly evolving with a modular plugin system, Lua scripting support, clipper functionality to redirect crypto payments, keylogging, and broad credential harvesting across browsers, wallets, and apps; researchers note code- and design-level overlap with Hidden Bee. Separately, Trend Micro analysis shows AsyncRAT abusing the legitimate aspnet_compiler.exe process for stealthy code injection, persistence, wallet discovery and C2 communication using DDNS, highlighting active, customizable malware campaigns and ongoing development by actors distributing these tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.