Skip to content

Malware

Rhadamanthys

According to PCrisk, Rhadamanthys is a stealer-type malware, and as its name implies - it is designed to extract data from infected machines.

Rhadamanthys is a Windows malware family operated by Sandworm.

Background

PCrisk classifies Rhadamanthys as a stealer-type malware, and true to its name, its purpose is to pull data off infected systems.

At the time of reporting, it was being distributed via malicious sites that impersonate those of legitimate applications like AnyDesk, Zoom, Notepad++, and more. Because Rhadamanthys arrives bundled with the genuine program, victims are less likely to grow suspicious right away. Operators pushed these decoy sites using Google ads that displaced the real entries in Google's search results.


Source: Malpedia (Fraunhofer FKIE).