A new offering named Rhadamanthys, a sophisticated information stealer, has surfaced for sale on underground marketplaces, with subscription packages starting at $299 and reaching up to $499 per month.
Marked by its polished branding and tiered pricing structure, the malware positions itself as a professional-grade service rather than a casual tool for novice cybercriminals.
Since its debut in September 2022 under the alias kingcrete2022, Rhadamanthys has evolved rapidly from an experimental project into one of the most feature-rich stealers on the dark web.
Initially drawing on code from a predecessor known as Hidden Bee, the authors refined its modular architecture to offer custom loaders, advanced obfuscation, and flexible deployment options.
Early versions relied on WAV or JPEG steganography to smuggle payloads, but the latest release, v0.9.2, simplifies delivery by embedding encrypted modules directly in PNG images.
Throughout its development, Rhadamanthys has adopted a “software house” approach—complete with a Tor-hosted storefront, Telegram support channels, and distinct brand identities such as RHAD Security and Mythical Origin Labs.

Its storefront boasts not only the flagship stealer but also complementary offerings like Elysium Proxy Bot and Crypt Service, underscoring the operators’ ambition to build a full cybercriminal ecosystem.
Tiered Pricing and Subscription Benefits
The operators market Rhadamanthys in three core tiers. The entry-level Self-Hosted package, priced at $299 per month, allows buyers to deploy the stealer on their own infrastructure.

This option appeals to threat actors with existing server capacity who wish to minimize third-party involvement. The mid-tier Managed Server subscription, at $499 per month, includes access to rented servers maintained by the developers, along with automated updates and prioritized technical support.
For organizations seeking full customization, an Enterprise package is available through individual negotiations, promising bespoke features, SLA guarantees, and dedicated assistance.
Such a business model is uncommon among stealers, many of which are offered as one-time sales or simple lifetime licenses.
By contrast, Rhadamanthys’ recurring subscription fees and ecosystem of services mirror legitimate software-as-a-service platforms, signaling a high degree of professionalism. Analysts warn that this professional veneer may attract advanced cybercrime groups who value reliability and ongoing support.
The Rhadamanthys configuration (described further) includes a 16-byte seed value that participates in mutex name generation. It is hashed along with the magic XRHY.

Beyond its pricing, Rhadamanthys’ latest iteration introduces several noteworthy enhancements.
A new message box mimicking the well-known Lumma stealer pop-up seeks to thwart analysts unpacking the loader. Custom executable formats (designated XS1B and XS2B) replace standard PE structures to frustrate automated tools, while RC4 has supplanted earlier XOR routines for string deobfuscation.
The malware’s configuration blob now begins with a 0xBEEF marker and supports multiple command-and-control (C2) URLs, compressed via LZO and encrypted with ChaCha20.
Evasion capabilities have also expanded. The “Strategy” module now fetches sandbox detection lists on demand, including MAC and hardware ID blocklists, default wallpaper checks, and sample file detection commonly used by analysis environments.
A randomized mutex seed thwarts universal vaccine techniques, and time synchronization checks against public NTP servers ensure the stealer’s operations remain covert.
Finally, the Netclient component manages payload delivery via PNG-based steganography, discarding earlier WAV and JPEG methods.
The stealer core executes inside a suspended legitimate process chosen from a configurable list, further complicating detection. Upon deployment, Rhadamanthys collects credentials, cookies, browser fingerprints, cryptocurrency wallet data, VPN configurations, and even integrates Lua-based plugins for extensive third-party software coverage.
With its subscription fees and continual refinements, Rhadamanthys exemplifies the growing trend of malware-as-a-service offerings adopting enterprise practices. Security teams are advised to update detection tools for PNG-delivered payloads, monitor for new mutex and configuration formats, and stay vigilant against the stealer’s evolving obfuscation techniques.
As Rhadamanthys cements itself as a sustainable revenue stream for its creators, defenders must anticipate further professionalization and feature extensions in future releases.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





