CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Rhadamanthys Stealer Adds Device Fingerprinting, PNG Steganography Payloads

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Rhadamanthys Stealer, a popular information stealer, has been updated to include device and web browser fingerprinting capabilities. The malware now uses PNG steganography to conceal its payloads. The threat actor behind Rhadamanthys has also advertised two additional tools, Elysium Proxy Bot and Crypt Service, on their website. The stealer's current version is 0.9.2, and it is available under a malware-as-a-service (MaaS) model with tiered pricing packages. The threat actor has rebranded themselves as "RHAD security" and "Mythical Origin Labs," indicating a long-term business venture. The stealer's capabilities have evolved significantly, posing a comprehensive threat to personal and corporate security. The latest updates include enhanced obfuscation techniques, environment checks, and a Lua runner for additional plugins.

Timeline

  1. 03.10.2025 18:58 1 articles · 6h ago

    Rhadamanthys Stealer Adds Device Fingerprinting and PNG Steganography

    Rhadamanthys Stealer version 0.9.2 has been updated to include device and web browser fingerprinting capabilities. The malware now uses PNG steganography to conceal its payloads. The threat actor behind Rhadamanthys has also advertised two additional tools, Elysium Proxy Bot and Crypt Service, on their website. The stealer's capabilities have evolved significantly, posing a comprehensive threat to personal and corporate security.

    Show sources

Information Snippets