logo

TA547 Phishing Attack Hits German Firms with Rhadamanthys Stealer

ID: 957172de-98f6-5926-9f39-8f4b2a462bba

STIX ID: report--957172de-98f6-5926-9f39-8f4b2a462bba

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-04-11

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

TA547 conducted an invoice-themed phishing campaign targeting dozens of German organizations that delivered the Rhadamanthys information stealer via a password-protected ZIP and a remote PowerShell loader (the loader contains grammatically detailed comments suggesting possible LLM generation); the report also details related credential-harvesting and loader campaigns, notable TTPs (compressed LNKs, AMSI bypass, Telegram-hosted scripts), and the actor's broader history as an IAB and distributor of various malware families.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.