Netskope Threat Labs

Rhadamanthys

ATP Sandbox Adv. HeuristicsNetskope IPS

Rhadamanthys is a modular information stealer sold as a subscription service that targets credentials, browser data, and cryptocurrency wallets on infected systems. Its implementation includes advanced evasion features, and its operators ship regular updates that add capabilities such as clipboard hijacking and screenshot capture. Distributors reach victims through malvertising, search engine poisoning, and fake software downloads, and stolen data feeds established criminal marketplaces.

First seen
January 2023
Last seen
October 2026
RhadamanthysStealer
Alert Name
ByteCode-MSIL.Spyware.Rhadamanthys
ByteCode-MSIL.Trojan.Rhadamanthys
Document-PDF.Trojan.Rhadamanthys
Script-BAT.Spyware.Rhadamanthys
Script-JS.Trojan.Rhadamanthys
Script-PowerShell.Spyware.Rhadamanthys
Script-PowerShell.Trojan.Rhadamanthys
Script-WScript.Spyware.Rhadamanthys
Win32.Downloader.Rhadamanthys
Win32.Exploit.Rhadamanthys