Rhadamanthys Malware Integration of AI Enhances Threat to Cryptocurrency Users

Date: June 15, 2024

Author: John Smith

In a significant advancement in the realm of cybersecurity, the Rhadamanthys information stealer malware has been updated with advanced new features, including the use of artificial intelligence (AI) for optical character recognition (OCR). This development dramatically escalates the malware's threat level, especially for those involved in cryptocurrency.

The latest updates to Rhadamanthys were detailed in an analysis by Recorded Future's Insikt Group. Version 0.7.0 of the malware introduces "Seed Phrase Image Recognition," a capability allowing the software to extract seed phrases from images of cryptocurrency wallets. These phrases are crucial for accessing wallet funds, thereby increasing the risk for anyone handling digital currencies.

"This allows Rhadamanthys to recognise seed phrase images on the client side and transmit them back to the command-and-control (C2) server for further exploitation," stated Recorded Future.

First detected in September 2022, Rhadamanthys has gained notoriety as a powerful information stealer distributed through the malware-as-a-service (MaaS) model. Despite being banned from underground forums such as Exploit and XSS, its developer, known by online aliases "kingcrete" or "kingcrete2022," has continued to promote the software on platforms like Telegram, Jabber, and TOX.

The malware is marketed on a subscription basis, costing $250 per month, or $550 for a three-month period. This price gives users the ability to collect a wide array of sensitive data from compromised systems, such as system information, credentials, cryptocurrency wallets, browser passwords, cookies, and application data. Rhadamanthys also takes steps to complicate analysis within sandbox environments, a tactic to evade detection and mitigation.

Upgraded Features and Capabilities

Version 0.7.0, released in June 2024, showcases a complete rewrite of both client-side and server-side frameworks, resulting in improved execution stability. The latest update builds on version 0.6.0, which was released in February 2024, by adding several new features, including 30 wallet-cracking algorithms and AI-powered image recognition. It also includes PDF recognition for extracting phrases and enhanced text extraction capabilities that can identify multiple saved phrases.

Furthermore, a new functionality allows threat actors to run Microsoft Software Installer (MSI) files. This addition is designed to bypass security solutions that might be present on the compromised host system. Also noteworthy is a feature that prevents re-execution within a configurable time frame, deterring multiple infections from overwhelming the system.

Rhadamanthys employs a versatile plugin system, enabling keylogger, cryptocurrency clipper, and reverse proxy functionalities, making it a popular choice among cybercriminals.

Global Security Concerns

The news of Rhadamanthys's advancements comes as Google's Mandiant revealed Lumma Stealer's employment of customised control flow indirection. This technique hampers binary analysis tools, frustrating reverse engineering processes designed to detect and disarm the malware.

Moreover, cybersecurity experts continue to witness updates across various malware families. For instance, Meduza, StealC, Vidar, and WhiteSnake have updated their capabilities to gather cookies from the Chrome web browser, bypassing new security measures. WhiteSnake Stealer has even introduced a feature to extract CVC codes from credit cards stored in Chrome.

In another development, an Amadey malware campaign employs an AutoIt script to launch victims' browsers in kiosk mode, coercing them into entering their Google account credentials for subsequent theft by information stealers like StealC.

Additionally, recent drive-by download attacks have tricked users into executing PowerShell commands following deceptive CAPTCHA verification, ultimately leading to installations of various stealer malware, including Lumma, StealC, and Vidar.

Implications and Reactions

This continual evolution of malware capabilities poses a sustained threat to global cybersecurity. Phishing and malvertising campaigns have also propagated threats like Atomic macOS Stealer (AMOS), Rilide, and a new variant of Snake Keylogger.

In parallel, a cybercrime gang identified as Marko Polo has used information stealers like Atomic, Rhadamanthys, and StealC in over 30 scam campaigns. These campaigns target cryptocurrency theft by impersonating legitimate brands in diverse sectors including online gaming and productivity software. Primarily targeting gamers, cryptocurrency influencers, and software developers, Marko Polo's spear-phishing efforts on social media have led to tens of thousands of compromised devices worldwide.

As malware continues to advance at an alarming pace, organisations and individuals must remain vigilant against the growing cybersecurity threats.

Source: Noah Wire Services