EXECUTIVE SUMMARY
A campaign targeting Israeli users has been identified, leveraging the RHADAMANTHYS information stealer. This malware, which surfaced offered as Malware-as-a-Service (MaaS) by Russian-speaking threat actors. The campaign employs highly targeted phishing emails in Hebrew, masquerading as communications from reputable Israeli media outlets like “Calcalist” and “Mako.” The emails aim to deceive recipients into downloading a malicious attachment, initiating the infection chain.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A campaign targeting Israeli users has been identified, leveraging the RHADAMANTHYS information stealer. This malware, which surfaced offered as Malware-as-a-Service (MaaS) by Russian-speaking threat actors. The campaign employs highly targeted phishing emails in Hebrew, masquerading as communications from reputable Israeli media outlets like “Calcalist” and “Mako.” The emails aim to deceive recipients into downloading a malicious attachment, initiating the infection chain.[emaillocker id="1283"]
The RHADAMANTHYS stealer employs a complex, multi-stage infection process. The attack begins with a locked RAR archive attachment that, once extracted, and executed, initiates various anti-analysis techniques such as virtual machine detection, debugger checks, and time-based evasion. The malware injects itself into legitimate Windows processes like OpenWith.exe, OOBE-Maintenance.exe, and dllhost.exe. It establishes persistence by modifying the Windows Registry to ensure it runs on startup. RHADAMANTHYS is designed to steal a wide range of sensitive information, including web browser data, cryptocurrency wallets, system information, and documents. It also takes screenshots and logs keystrokes. The malware communicates with its command and control (C2) servers using encrypted channels, primarily over and can download additional payloads to the infected system.
The RHADAMANTHYS stealer represents a significant evolution in the threat landscape, combining advanced anti-analysis features with comprehensive data theft capabilities. Its targeted attack on Israeli users underscores the increasing of MaaS offerings and the localized focus of modern campaigns. The potential for both financial and geopolitical motivations behind this campaign highlights the need for vigilant practices and robust defenses to protect against such threats.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| Execution | T1203 | Exploitation for Client Execution |
| Persistence | T1547 | Boot or Logon Autostart Execution |
| Defense Evasion | T1055 | Process Injection |
| T1497 | Virtualization/Sandbox Evasion | |
| T1622 | Debugger Evasion | |
| Credential Access | T1555 | Credentials from Password Stores |
| Collection | T1056 | Input Capture |
| T1213 | Data from Information Repositories | |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
| Impact | T1565 | Data Manipulation |
REFERENCES:
The following reports contain further technical details:
https://cybersecuritynews.com/rhadamanthys-stealer-rar-credentials/