Main menu

Pages

the hidden data thief on Google

Rhadamanthys: the hidden data thief on Google

Thieves are viruses that enter your PC to steal as much data as possible. If they are not new, then a recently appeared thief is extremely dangerous.

Like all stealer viruses, Rhadamanthys penetrates into a computer system and steals everything: bank details, personal details, passwords. New on the other hand, Rhadamanthys also steals access to your cryptocurrency wallets which hackers can thus empty.

How does Rhadamanthys infiltrate?

Young youtuber, you want to record your video games, but you don’t have enough income on your Youtube channel to buy paid software. No problem, after a quick Google search, you come across articles discussing OBS Studio. This freeware lets you film your screen, which is perfect for recording your gameplay. You type OBS Studio in the search bar and click on one of the first links, you install the software, but nothing happens… Finally, click on another link and the software installs and works. However, unbeknownst to you, the first installation attempt didn’t fail, it just didn’t install OBS Studio, it did Rhadamanthys.

Once there, it steals all your data and once it’s done with its job, it deletes itself. No trace of his passage, a perfect crime. For the victim to realize the theft, she will have to be alerted of suspicious movements on her Paypal or when she discovers that her crypto wallet is now empty. Until industry exponents sounded the alarm bells like SentinelOne, Rhadamanthys camouflaged itself in the first Google-sponsored links to download OBS Studio, links that are precisely advertisements, as specified by the word “Advertisement” above them . From now on the virus camouflages itself in other yet unknown links and certainly also in infected cookies like other stealers do.

A thief as a service

Who is behind Rhadamanthys? We don’t know yet, but what is certain is that its creators are selling it on the darknet in the form of a subscription. No need to develop your own thief, just pay and easy data theft is yours. It will cost between $59 for one-week access and $999 for lifetime access.

An announcement for Rhadamanthys from the darknet. © Screenshot

To understand the origin of this thief’s name, we can already observe that the promotional logo of Rhadamanthys shows a dragon. The name is actually a reference to the manga Saint Seiya (Knights of the Zodiac in French). One of the main enemies of the heroes of this manga is called: Rhadamanthys or Rhadamanthe depending on the version. His armor, as the name suggests, is shaped like a wyvern or vouivre in French, a mythological dragon-like animal. The hackers behind this thief are undoubtedly fans of Masami Kurumada’s work.

Comments