Cyber Security News

Threats Actors Using Copyright Phishing Lures to Deliver Rhadamanthys Stealer

A sophisticated phishing campaign leveraging copyright infringement themes has emerged as a primary vector for distributing the dangerous Rhadamanthys information stealer malware across European countries.

Since April 2025, threat actors have been exploiting fear-based social engineering tactics, impersonating legal representatives and law firms to deceive victims into believing they have violated copyright laws on social media platforms.

The campaign represents a significant escalation in the tactics employed by cybercriminals to bypass traditional security measures and establish persistent access to sensitive systems.

The malicious operation has demonstrated remarkable geographic scope, with confirmed targeting across sixteen European nations including Germany, Italy, Spain, the United Kingdom, Poland, and several Eastern European countries.

The attackers employ highly localized phishing emails crafted in region-specific languages to increase credibility and user engagement, making the threats appear legitimate to unsuspecting recipients.

These emails typically arrive with urgent language demanding immediate action within 48 hours, claiming serious legal consequences including financial penalties if recipients fail to address alleged copyright violations.

Cybereason analysts identified this renewed campaign as part of a broader trend where threat actors exploit the legitimate concerns of content creators and multimedia professionals who frequently handle copyrighted materials in their daily work.

The researchers noted that the campaign specifically targets individuals in photography, video production, and music industries, who are more likely to have multimedia tools that rely on specific Dynamic Link Libraries (DLLs) such as ffmpeg.dll.

This targeting strategy proves particularly effective because these professionals often work as external contractors or freelancers, potentially lacking enterprise-grade security protections like Endpoint Detection and Response (EDR) systems.

Phishing email from the Rhadamanthys campaign from a reported incident (Source – Cyberson)

The attack vector begins with carefully crafted phishing emails containing malicious download links leading to archives hosted on services like Mediafire through newly registered domains acting as redirects.

When victims click these links, they are directed through a complex redirection chain involving URL shortening services such as tr.ee, t2m.co, and goo.su, ultimately leading to the download of large ZIP archives containing the malicious payload.

The substantial file sizes, often reaching approximately 500 megabytes, serve as an additional evasion technique, as many security solutions skip detailed inspection of such large payloads due to performance considerations.

Advanced DLL Side-Loading Technique Enables Stealthy Code Execution

The core infection mechanism relies on a sophisticated DLL side-loading attack that exploits the behavior of a legitimate but outdated Haihaisoft PDF Reader application.

The downloaded archive contains three critical components: a legitimate PDF reader executable renamed to match the phishing lure (such as “Proof_of_copyright_infringement.exe”), a malicious DLL named msimg32.dll, and a decoy document to maintain the illusion of legitimacy.

The attack leverages Windows’ default DLL search order behavior, where applications first attempt to load required libraries from their own directory before searching system locations.

The malicious msimg32.dll is strategically placed alongside the legitimate executable, ensuring it gets loaded instead of the genuine Windows system library.

Attack flow diagram related to execution of the Rhadamantys loader (Source – Cyberson)

This technique allows the malware to execute within the context of a trusted process, significantly reducing the likelihood of detection by security software.

Once executed, the malicious DLL employs Thread Local Storage (TLS) callbacks to initialize malicious code before the main program entry point runs.

The malware incorporates advanced evasion techniques including the Heaven’s Gate method for transitioning between 32-bit and 64-bit execution contexts, enabling it to bypass user-mode API hooking mechanisms commonly employed by security solutions.

For persistence, the malware creates a copy of itself in the user’s Documents folder with the filename “VolkUpdater0987.dll” and establishes an autorun registry entry using the command:-

reg add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Volk Sensor" /t REG_SZ /d "rundll32.exe C:\Users\[username]\Documents\VolkUpdater0987.dll,EntryPoint" /f

The malware then proceeds to download and execute the final Rhadamanthys stealer payload from command and control servers, initiating comprehensive data theft operations targeting stored credentials, browser data, cryptocurrency wallets, and other sensitive information stored on infected systems.

Equip your SOC team with deep threat analysis for faster response -> Get Extra 𝗦𝗮𝗻𝗱𝗯𝗼𝘅 𝗹𝗶𝗰𝗲𝗻𝘀𝗲𝘀 for Free

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

4 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

9 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

20 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

15 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

16 hours ago