2 Sources
[1]
Scammers are using fake copyright infringement claims to hack businesses
The crooks are impersonating entertainment, media, and tech firms Scammers have been spotted sending out fake copyright infringement violation claims as part of a new phishing campaign aiming to spread the latest version of the Rhadamanthys Stealer malware. Cybersecurity researchers Check Point
[2]
Cybercrims target global orgs using fake copyright notices
Organizations should be on the lookout for bogus copyright infringement emails as they might be the latest ploy by cybercriminals to steal their data. The most recent version of the Rhadamanthys infostealer malware is being spread far and wide, targeting organizations across multiple continents,
Share
Copy Link
Cybercriminals are leveraging fake copyright infringement notices to distribute the latest version of Rhadamanthys Stealer malware, utilizing AI capabilities for more efficient attacks.

A new phishing campaign dubbed CopyRh(ight)adamanthys has been uncovered, targeting organizations worldwide with fake copyright infringement claims. The campaign, active since July, aims to spread the latest version of the Rhadamanthys Stealer malware
1
.Cybercriminals are impersonating entertainment, media, and tech firms, which account for 70% of the spoofed organizations. The attackers use dedicated Gmail accounts and leverage AI capabilities to create convincing phishing emails and automate their attacks
1
.The latest version of Rhadamanthys (0.7) claims to have advanced AI-driven features. However, researchers at Check Point Software have found that it primarily uses older machine learning techniques, particularly in optical character recognition (OCR)
2
.The phishing emails contain a password-protected ZIP archive with a decoy PDF, an executable, and a DLL. When executed, the malware is unpacked and deployed, capable of stealing sensitive information including:
1
2
The campaign has a wide reach, targeting organizations across multiple continents. Countries affected include the US, Israel, South Korea, Peru, Thailand, Spain, Switzerland, and Poland
2
.Related Stories
Despite initial suspicions of state-sponsored activity, the indiscriminate targeting and financially motivated tactics suggest that lower-level criminals are behind the campaign. The attackers aim to profit either by directly siphoning funds from cryptocurrency wallets or by selling stolen credentials
2
.Sergey Shykevich, threat intelligence group manager at Check Point Software, emphasized the need for security leaders to prioritize automation and AI in defense strategies to counteract these globally scaled, financially motivated phishing campaigns
2
.As the threat landscape continues to evolve, organizations must remain vigilant and adapt their security measures to combat increasingly sophisticated attacks that leverage AI and automation techniques.
Summarized by
Navi
[2]
30 May 2025•Technology

11 Jul 2025•Technology

19 Nov 2024•Technology

1
Technology

2
Policy and Regulation

3
Technology
