Sunday, September 13, 2026

Rhadamanthys Stealer Offered on Dark Web for $299–$499

A new offering named Rhadamanthys, a sophisticated information stealer, has surfaced for sale on underground marketplaces, with subscription packages starting at $299 and reaching up to $499 per month.

Marked by its polished branding and tiered pricing structure, the malware positions itself as a professional-grade service rather than a casual tool for novice cybercriminals.

Since its debut in September 2022 under the alias kingcrete2022, Rhadamanthys has evolved rapidly from an experimental project into one of the most feature-rich stealers on the dark web.

Initially drawing on code from a predecessor known as Hidden Bee, the authors refined its modular architecture to offer custom loaders, advanced obfuscation, and flexible deployment options.

Early versions relied on WAV or JPEG steganography to smuggle payloads, but the latest release, v0.9.2, simplifies delivery by embedding encrypted modules directly in PNG images.

Throughout its development, Rhadamanthys has adopted a “software house” approach—complete with a Tor-hosted storefront, Telegram support channels, and distinct brand identities such as RHAD Security and Mythical Origin Labs.

Attackers’ website, main view.
Attackers’ website, main view.

Its storefront boasts not only the flagship stealer but also complementary offerings like Elysium Proxy Bot and Crypt Service, underscoring the operators’ ambition to build a full cybercriminal ecosystem.

Tiered Pricing and Subscription Benefits

The operators market Rhadamanthys in three core tiers. The entry-level Self-Hosted package, priced at $299 per month, allows buyers to deploy the stealer on their own infrastructure.

The attackers’ website: pricing of Rhadamanthys.
The attackers’ website: pricing of Rhadamanthys.

This option appeals to threat actors with existing server capacity who wish to minimize third-party involvement. The mid-tier Managed Server subscription, at $499 per month, includes access to rented servers maintained by the developers, along with automated updates and prioritized technical support.

For organizations seeking full customization, an Enterprise package is available through individual negotiations, promising bespoke features, SLA guarantees, and dedicated assistance.

Such a business model is uncommon among stealers, many of which are offered as one-time sales or simple lifetime licenses.

By contrast, Rhadamanthys’ recurring subscription fees and ecosystem of services mirror legitimate software-as-a-service platforms, signaling a high degree of professionalism. Analysts warn that this professional veneer may attract advanced cybercrime groups who value reliability and ongoing support.

The Rhadamanthys configuration (described further) includes a 16-byte seed value that participates in mutex name generation. It is hashed along with the magic XRHY.

 Fragment of the function responsible for generation of the Mutex name.
 Fragment of the function responsible for generation of the Mutex name.

Beyond its pricing, Rhadamanthys’ latest iteration introduces several noteworthy enhancements.

A new message box mimicking the well-known Lumma stealer pop-up seeks to thwart analysts unpacking the loader. Custom executable formats (designated XS1B and XS2B) replace standard PE structures to frustrate automated tools, while RC4 has supplanted earlier XOR routines for string deobfuscation.

The malware’s configuration blob now begins with a 0xBEEF marker and supports multiple command-and-control (C2) URLs, compressed via LZO and encrypted with ChaCha20.

Evasion capabilities have also expanded. The “Strategy” module now fetches sandbox detection lists on demand, including MAC and hardware ID blocklists, default wallpaper checks, and sample file detection commonly used by analysis environments.

A randomized mutex seed thwarts universal vaccine techniques, and time synchronization checks against public NTP servers ensure the stealer’s operations remain covert.

Finally, the Netclient component manages payload delivery via PNG-based steganography, discarding earlier WAV and JPEG methods.

The stealer core executes inside a suspended legitimate process chosen from a configurable list, further complicating detection. Upon deployment, Rhadamanthys collects credentials, cookies, browser fingerprints, cryptocurrency wallet data, VPN configurations, and even integrates Lua-based plugins for extensive third-party software coverage.

With its subscription fees and continual refinements, Rhadamanthys exemplifies the growing trend of malware-as-a-service offerings adopting enterprise practices. Security teams are advised to update detection tools for PNG-delivered payloads, monitor for new mutex and configuration formats, and stay vigilant against the stealer’s evolving obfuscation techniques.

As Rhadamanthys cements itself as a sustainable revenue stream for its creators, defenders must anticipate further professionalization and feature extensions in future releases.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Related Articles

Recent News