A sophisticated phishing campaign leveraging copyright infringement themes has emerged as a primary vector for distributing the dangerous Rhadamanthys information stealer malware across European countries.
Since April 2025, threat actors have been exploiting fear-based social engineering tactics, impersonating legal representatives and law firms to deceive victims into believing they have violated copyright laws on social media platforms.
The campaign represents a significant escalation in the tactics employed by cybercriminals to bypass traditional security measures and establish persistent access to sensitive systems.
The malicious operation has demonstrated remarkable geographic scope, with confirmed targeting across sixteen European nations including Germany, Italy, Spain, the United Kingdom, Poland, and several Eastern European countries.
The attackers employ highly localized phishing emails crafted in region-specific languages to increase credibility and user engagement, making the threats appear legitimate to unsuspecting recipients.
These emails typically arrive with urgent language demanding immediate action within 48 hours, claiming serious legal consequences including financial penalties if recipients fail to address alleged copyright violations.
Cybereason analysts identified this renewed campaign as part of a broader trend where threat actors exploit the legitimate concerns of content creators and multimedia professionals who frequently handle copyrighted materials in their daily work.
The researchers noted that the campaign specifically targets individuals in photography, video production, and music industries, who are more likely to have multimedia tools that rely on specific Dynamic Link Libraries (DLLs) such as ffmpeg.dll.
This targeting strategy proves particularly effective because these professionals often work as external contractors or freelancers, potentially lacking enterprise-grade security protections like Endpoint Detection and Response (EDR) systems.
The attack vector begins with carefully crafted phishing emails containing malicious download links leading to archives hosted on services like Mediafire through newly registered domains acting as redirects.
When victims click these links, they are directed through a complex redirection chain involving URL shortening services such as tr.ee, t2m.co, and goo.su, ultimately leading to the download of large ZIP archives containing the malicious payload.
The substantial file sizes, often reaching approximately 500 megabytes, serve as an additional evasion technique, as many security solutions skip detailed inspection of such large payloads due to performance considerations.
The core infection mechanism relies on a sophisticated DLL side-loading attack that exploits the behavior of a legitimate but outdated Haihaisoft PDF Reader application.
The downloaded archive contains three critical components: a legitimate PDF reader executable renamed to match the phishing lure (such as “Proof_of_copyright_infringement.exe”), a malicious DLL named msimg32.dll, and a decoy document to maintain the illusion of legitimacy.
The attack leverages Windows’ default DLL search order behavior, where applications first attempt to load required libraries from their own directory before searching system locations.
The malicious msimg32.dll is strategically placed alongside the legitimate executable, ensuring it gets loaded instead of the genuine Windows system library.
This technique allows the malware to execute within the context of a trusted process, significantly reducing the likelihood of detection by security software.
Once executed, the malicious DLL employs Thread Local Storage (TLS) callbacks to initialize malicious code before the main program entry point runs.
The malware incorporates advanced evasion techniques including the Heaven’s Gate method for transitioning between 32-bit and 64-bit execution contexts, enabling it to bypass user-mode API hooking mechanisms commonly employed by security solutions.
For persistence, the malware creates a copy of itself in the user’s Documents folder with the filename “VolkUpdater0987.dll” and establishes an autorun registry entry using the command:-
reg add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Volk Sensor" /t REG_SZ /d "rundll32.exe C:\Users\[username]\Documents\VolkUpdater0987.dll,EntryPoint" /f The malware then proceeds to download and execute the final Rhadamanthys stealer payload from command and control servers, initiating comprehensive data theft operations targeting stored credentials, browser data, cryptocurrency wallets, and other sensitive information stored on infected systems.
Equip your SOC team with deep threat analysis for faster response -> Get Extra 𝗦𝗮𝗻𝗱𝗯𝗼𝘅 𝗹𝗶𝗰𝗲𝗻𝘀𝗲𝘀 for Free
Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…
DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…
Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…