logo

New Phishing Campaign Targets Oil & Gas with Evolved Data-Stealing Malware

ID: 41ec87cb-4b3f-5bc9-9373-c2a519e48b3f

STIX ID: report--41ec87cb-4b3f-5bc9-9373-c2a519e48b3f

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-04-04

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

An updated Rhadamanthys information‑stealer is being distributed via targeted phishing campaigns against the oil and gas sector: emails employ a vehicle-incident lure and an open-redirect to present an image that, when clicked, downloads a ZIP containing the C++ stealer which contacts command-and-control servers to exfiltrate sensitive data. The report links this activity to broader stealer trends (Agent Tesla, Sync-Scheduler, Mighty Stealer), describes delivery and obfuscation techniques (RoundCube webmail, PDF/image lure), and notes historical bundling with LockBit payloads, indicating ongoing evolution and active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.