<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/rhadamantys-stealer-exploits-fake-copyright-infringement-emails-rsj22gukm" -->

---
title: Rhadamantys Stealer Exploits Fake Copyright Infringement...
description: Cybercriminals are using fake copyright infringement emails to distribute the Rhadamanthys infostealer malware globally, targeting organizations by accusing...
canonical: https://daily.dev/posts/rhadamantys-stealer-exploits-fake-copyright-infringement-emails-rsj22gukm
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Rhadamantys Stealer Exploits Fake Copyright Infringement Emails | daily.dev
og:description: Cybercriminals are using fake copyright infringement emails to distribute the Rhadamanthys infostealer malware globally, targeting organizations by accusing...
og:url: https://daily.dev/posts/rhadamantys-stealer-exploits-fake-copyright-infringement-emails-rsj22gukm
og:image: https://api.daily.dev/og/posts/rSj22GuKm.png
og:image:alt: Rhadamantys Stealer Exploits Fake Copyright Infringement Emails
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Rhadamantys Stealer Exploits Fake Copyright Infringement Emails

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

Cybercriminals are using fake copyright infringement emails to distribute the Rhadamanthys infostealer malware globally, targeting organizations by accusing them of Facebook copyright violations. The malware, active since July 2024, employs advanced tactics such as AI-powered OCR to steal sensitive data. Additionally, the campaign spreads another malware, SteelFox, using driver exploits to mine cryptocurrency and steal credit card information. Security experts emphasize the need for robust defense strategies and continuous monitoring to combat these sophisticated threats.

## Content

# Fake Copyright Infringement Emails Distribute Rhadamanthys Malware Globally

Cybercriminals are increasingly using sophisticated tactics to target global organizations, leveraging fake copyright infringement emails to spread the Rhadamanthys infostealer malware. This campaign, known as CopyRh(ight)adamantys, has been actively deceiving victims since July 2024 by falsely accusing companies of copyright violations on Facebook.

## Tactics and Techniques

The phishing emails often originate from newly created domains and claim that the targeted businesses have violated copyrights. These messages typically contain a ZIP archive with malicious files, including a document and a DLL infostealer. Upon opening the archive, victims inadvertently download the malware, which then proceeds to steal sensitive information such as credentials, cryptocurrency seed phrases, and other private data.

The latest version of Rhadamanthys incorporates advanced tactics, including AI-powered optical character recognition (OCR) for extracting data from documents and images. Despite some language errors in the AI module, the malware's sophistication allows it to target victims across the U.S., Europe, East Asia, and South America.

## Additional Threats and Wider Campaign

The campaign not only uses copyright infringement themes but also employs driver exploits to distribute another malware named SteelFox. This malware, spread through forums and torrent trackers, exploits vulnerabilities in Windows drivers to steal credit card information and mine cryptocurrency.

Researchers from Check Point Research have linked some of the Rhadamanthys operations to Iranian actor Void Manticore. The highly organized nature of the campaign suggests financial motives rather than state sponsorship.

## Security Measures

Security experts highlight the importance of incorporating automation and AI in defense strategies to counter such sophisticated phishing campaigns. Using larger file versions of the malicious payloads, attackers attempt to evade antivirus detection, making robust cybersecurity measures and continuous monitoring essential.

Organizations should remain vigilant against unsolicited emails claiming copyright issues and ensure their security systems are equipped to handle advanced threats like Rhadamanthys and SteelFox.

## Similar posts on daily.dev

- [Governing Security in the Age of Infinite Signal](https://daily.dev/posts/governing-security-in-the-age-of-infinite-signal-qhihbir44) · Snyk · 0 upvotes · 0 comments
- [No one has a good plan for how AI companies should work with the government](https://daily.dev/posts/no-one-has-a-good-plan-for-how-ai-companies-should-work-with-the-government-nkajqoze1) · TechCrunch · 0 upvotes · 1 comments

---

Tags: [#ai](https://daily.dev/tags/ai), [#cyber](https://daily.dev/tags/cyber), [#malware](https://daily.dev/tags/malware), [#phishing](https://daily.dev/tags/phishing)

[View this post on daily.dev](https://daily.dev/posts/rhadamantys-stealer-exploits-fake-copyright-infringement-emails-rsj22gukm)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Rhadamantys Stealer Exploits Fake Copyright Infringement Emails","url":"https://daily.dev/posts/rhadamantys-stealer-exploits-fake-copyright-infringement-emails-rsj22gukm","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/rhadamantys-stealer-exploits-fake-copyright-infringement-emails-rsj22gukm"},"datePublished":"2024-11-06T22:52:03.047Z","dateModified":"2024-11-07T22:21:12.866Z","description":"Cybercriminals are using fake copyright infringement emails to distribute the Rhadamanthys infostealer malware globally, targeting organizations by accusing...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/2aff509e172ab5949b036009604d4f54?_a=AQAEuj9","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/2aff509e172ab5949b036009604d4f54?_a=AQAEuj9","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/rhadamantys-stealer-exploits-fake-copyright-infringement-emails-rsj22gukm","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"ai,cyber,malware,phishing","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Rhadamantys Stealer Exploits Fake Copyright Infringement Emails"}]}
```

