The Rhadamanthys infostealer disrupted operation marks another major blow to cybercriminal networks. Researchers report that the malware’s infrastructure went offline after its operators lost access to critical servers, suggesting a coordinated law enforcement intervention.

Suspected Law Enforcement Takedown

Security researchers including g0njxa and Gi7w0rm revealed that Rhadamanthys customers could no longer log into their control panels. Instead of password prompts, the panels now demanded client certificates, indicating server reconfiguration. Hacker forum posts soon appeared, warning that “German police are acting” and urging users to erase data immediately.

The Rhadamanthys developers also noticed unusual logins traced to German IP addresses before total access loss. These signs strongly suggest that law enforcement seized control of the infrastructure rather than it simply failing.

How Rhadamanthys Operated

Rhadamanthys was a subscription-based infostealer that targeted browsers, cryptocurrency wallets, and authentication tokens. Buyers accessed stolen data through a “smart panel” that centralized logs from infected systems. The malware was popular on dark web markets due to its speed, user-friendly dashboard, and ability to bypass antivirus software.

The operation’s Tor websites and clear web portals went offline soon after the disruption. No seizure notice has appeared, but the timing aligns with Operation Endgame, a global campaign targeting major malware services.

Broader Impact on Cybercrime

Many active data-theft campaigns relying on Rhadamanthys were suddenly halted. Cybercriminals have expressed frustration over lost access to stolen credentials, further proving the takedown’s effectiveness. Analysts believe this marks another example of how multi-agency collaboration is limiting underground trade in stolen data.

Conclusion

The Rhadamanthys infostealer disrupted event demonstrates how coordinated law enforcement actions can dismantle large-scale cybercrime ecosystems. As global operations like Endgame expand, similar disruptions are expected across malware networks worldwide.


0 responses to “Rhadamanthys Infostealer Disrupted After Cybercriminals Lose Server Access”