Just Another Blue Teamer · @LeeArchinal
53 followers · 77 posts · Server ioc.exchange

Happy Monday everyone! I know it's a little late and I am not going to deny that the picture with the article really helped this one become my ! Brought to you by the Check Point Software Technologies Ltd Research team, this article provides not only insight to the but context surrounding creation, functionality, technical analysis, and behaviors. Known as the Stealer, this malware author appears to have given it every functionality needed by any cyber criminal. Enjoy and Happy Hunting!

RHADAMANTHYS: THE “EVERYTHING BAGEL” INFOSTEALER
research.checkpoint.com/2023/r

#readoftheday #infostealer #rhadamanthys #cybersecurity #itsecurity #infosec #blueteam #threatintel #threathunting #ThreatDetection #happyhunting

Last updated 1 year ago

Anonymous :anarchism: 🏴 · @YourAnonRiots
5381 followers · 32103 posts · Server mstdn.social

TOP10 last week's threats by uploads 📊

⬆️ 517 (478)
⬆️ 287 (182)
⬇️ 175 (212)
⬇️ 150 (302)
⬆️ 141 (111)
⬆️ 133 (102)
⬆️ 132 (67)
⬇️ 119 (143)
⬇️ 96 (101)
⬆️ 87 (26)

any.run/malware-trends/?utm_so

#Ransomware #CyberSecurity #InfoSec #rhadamanthys #njrat #snake #smoke #AsyncRAT #qbot #emotet #remcos #amadey #redline

Last updated 1 year ago

Don Carlos · @engmorales
1 followers · 6 posts · Server techhub.social

RT SwiftOnSecurity: 😎 Google Ad Executives 😎
Looks like money

QT 1ZRR4H: 1/ THIS IS BAD!!!

Search for "OBS" in Google and you get, not 1, but 5 (❗️) malicious ads in the first links/results 😱

All part of a new stealer campaign with new tricks and mainly targeting streamers.

#rhadamanthys

Last updated 2 years ago

FairlySadPanda · @FairlySadPanda
61 followers · 679 posts · Server mastodon.social

Meanwhile it is totally fine on DuckDuckGo, which is a universally superior engine anyway. If you want decent search results, get off Google

RT @1ZRR4H@twitter.com

1/ THIS IS BAD!!!

Search for "OBS" in Google and you get, not 1, but 5 (❗️) malicious ads in the first links/results 😱

All part of a new stealer campaign with new tricks and mainly targeting streamers.

🐦🔗: twitter.com/1ZRR4H/status/1614

#rhadamanthys

Last updated 2 years ago

· @Mud
1 followers · 3 posts · Server infosec.exchange

TradingView leading to infection

Delivery:
hxxps://tradingwiv[.]com
hxxp://dropbox[.]com/s/kvtg7pwzb4a0xu0/TradingVlew_x32_x64_bit.zip?dl=1

: 179.43.142.109

#seopoisoning #rhadamanthys #c2

Last updated 2 years ago

· @Mud
2 followers · 3 posts · Server infosec.exchange

Fake/backdoored game cheats leading to infection

Delivery:
hxxps://ominate[.]io
hxxps://github[.]com/t4ppe/HyperVisor-Injector
hxxps://www.tiktok[.]com/@codmodss
hxxps://discord[.]gg/wzmods

: 91.202.5.208

Panel: hxxp://91.202.5.208:443/admin/console/index.html

#rhadamanthys #c2

Last updated 2 years ago

· @Mud
2 followers · 3 posts · Server infosec.exchange

GPU-Z leading to infection

Delivery: hxxps://download-gpuz[.]net

: 152.89.198.59

Panel: hxxp://152.89.198.59:443/admin/console/index.html

#seopoisoning #rhadamanthys #c2

Last updated 2 years ago

RT @1ZRR4H@twitter.com

1/ THIS IS BAD!!!

Search for "OBS" in Google and you get, not 1, but 5 (❗️) malicious ads in the first links/results 😱

All part of a new stealer campaign with new tricks and mainly targeting streamers.

🐦🔗: twitter.com/1ZRR4H/status/1614

#rhadamanthys

Last updated 2 years ago

TropChaud · @IntelScott
192 followers · 36 posts · Server infosec.exchange

seems to be having a moment right now. Quick rundown on what we know about infection trends & its post-exploit TTPs

Discovered last summer, it's one of several popular & emerging with new/improved evasion and/or theft capabilities observed in recent months. Like many popular families, Rhadamanthys initial infections occur via multiple vectors, including & email attachments and - increasingly - legitimate web search ads: malware-traffic-analysis.net/2, blog.cyble.com/2023/01/12/rhad

In our broad analysis of the infostealer threat landscape, we identified TTPs associated with 16 families across dozens of public reports. We've already added more reported techniques to Rhadamanthys' set since the report dropped this week tidalcyber.com/blog/big-game-s

Still somewhat limited public reporting on this threat to date, although we've identified 22 (sub-)techniques associated with Rhadamanthys so far. Visualize them and pivot to associated defensive & offensive testing capabilities here: app.tidalcyber.com/share/techn

In addition to the reports above, two other resources here: accenture.com/us-en/blogs/secu, threatmon.io/rhadamanthys-stea. Thanks to the teams that published great reporting & analysis around Rhadamanthys so far, including ThreatMon Accenture @malware_traffic & Cyble

#rhadamanthys #stealer #infostealer #malware #phishing #spam #mitreattack #threatinformeddefense #credentials #cookies #mfa #2fa

Last updated 2 years ago

Brad · @malware_traffic
2104 followers · 87 posts · Server infosec.exchange

2023-01-12 (Thursday) - Google Ad --> Fake Notepad++ site textedit-notepad[.]com --> ()

I carved the inflated 777 MB EXE to remove all the padding. Sample available at:

- bazaar.abuse.ch/sample/2a4637e

- tria.ge/230113-eqwwfahg9v

- app.any.run/tasks/3d9a4477-305

C2 traffic:

- hxxp://164.90.172[.]224/blob/oo6nbv.a50a

#rhadamanthys #rhadamanthysstealer

Last updated 2 years ago

stealer
f6afb455020564659589c2b34d9364b7

#rhadamanthys

Last updated 2 years ago

TropChaud · @IntelScott
180 followers · 28 posts · Server infosec.exchange

Infection Trends: Impersonating Legitimate Software

As actors saw success using -derived creds in attacks on major orgs last year, @tidalcyber anticipates the infostealer threat for businesses is rising heading into 2023, with search ad abuse a top vector

2023 threat landscape briefing next Tuesday, January 10, noon Eastern with more details: hubs.la/Q01v-PN00

(Infographic is already out of date with @malware_traffic 's latest blog on distributed via an ad for a fake Notepad++ download. Update forthcoming! malware-traffic-analysis.net/2)

#infostealer #stealer #rhadamanthys

Last updated 2 years ago