Threat Advisory

RHADAMANTHYS Stealer Weaponizing RAR Archive to Steal Login Credentials

Threat: Malware
Targeted Region: Isarel
Threat Actor Region: Russia
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A campaign targeting Israeli users has been identified, leveraging the RHADAMANTHYS information stealer. This malware, which surfaced offered as Malware-as-a-Service (MaaS) by Russian-speaking threat actors. The campaign employs highly targeted phishing emails in Hebrew, masquerading as communications from reputable Israeli media outlets like “Calcalist” and “Mako.” The emails aim to deceive recipients into downloading a malicious attachment, initiating the infection chain.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A campaign targeting Israeli users has been identified, leveraging the RHADAMANTHYS information stealer. This malware, which surfaced offered as Malware-as-a-Service (MaaS) by Russian-speaking threat actors. The campaign employs highly targeted phishing emails in Hebrew, masquerading as communications from reputable Israeli media outlets like “Calcalist” and “Mako.” The emails aim to deceive recipients into downloading a malicious attachment, initiating the infection chain.[emaillocker id="1283"]

 

The RHADAMANTHYS stealer employs a complex, multi-stage infection process. The attack begins with a locked RAR archive attachment that, once extracted, and executed, initiates various anti-analysis techniques such as virtual machine detection, debugger checks, and time-based evasion. The malware injects itself into legitimate Windows processes like OpenWith.exe, OOBE-Maintenance.exe, and dllhost.exe. It establishes persistence by modifying the Windows Registry to ensure it runs on startup. RHADAMANTHYS is designed to steal a wide range of sensitive information, including web browser data, cryptocurrency wallets, system information, and documents. It also takes screenshots and logs keystrokes. The malware communicates with its command and control (C2) servers using encrypted channels, primarily over and can download additional payloads to the infected system.

 

The RHADAMANTHYS stealer represents a significant evolution in the threat landscape, combining advanced anti-analysis features with comprehensive data theft capabilities. Its targeted attack on Israeli users underscores the increasing of MaaS offerings and the localized focus of modern campaigns. The potential for both financial and geopolitical motivations behind this campaign highlights the need for vigilant practices and robust defenses to protect against such threats.

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access T1566 Phishing
Execution T1203 Exploitation for Client Execution
Persistence T1547 Boot or Logon Autostart Execution
Defense Evasion T1055 Process Injection
T1497 Virtualization/Sandbox Evasion
T1622 Debugger Evasion
Credential Access T1555 Credentials from Password Stores
Collection T1056 Input Capture
T1213 Data from Information Repositories
Exfiltration T1041 Exfiltration Over C2 Channel
 Impact T1565 Data Manipulation

REFERENCES:

The following reports contain further technical details:
https://cybersecuritynews.com/rhadamanthys-stealer-rar-credentials/

[/emaillocker]
crossmenu