{"id":3024,"date":"2025-03-30T07:06:01","date_gmt":"2025-03-30T06:06:01","guid":{"rendered":"https:\/\/aegislens.com\/home\/?p=3024"},"modified":"2025-03-30T07:06:01","modified_gmt":"2025-03-30T06:06:01","slug":"unpacking-encrypthub-windows-zero-day-exploitation-for-rhadamanthys-and-stealc-malware-deployment","status":"publish","type":"post","link":"https:\/\/aegislens.com\/home\/unpacking-encrypthub-windows-zero-day-exploitation-for-rhadamanthys-and-stealc-malware-deployment\/","title":{"rendered":"Unpacking EncryptHub: Windows Zero-Day Exploitation for Rhadamanthys and StealC Malware Deployment"},"content":{"rendered":"<p>&#8221; said one senior cybersecurity researcher. <\/p>\n<p><strong>Body:<\/strong><\/p>\n<p>Cybersecurity professionals have detected a new campaign by the cybercriminal group EncryptHub that exploits a specific Windows zero-day vulnerability to deploy Rhadamanthys and StealC malware.<\/p>\n<p>The exploitation manipulates the Windows Management Instrumentation Command-line (WMIC) by using .msc files and the Multilingual User Interface Path (MUIPath).<\/p>\n<p>The threat actors primarily aim to compromise various sensitive user data.<\/p>\n<p>Once the Windows zero-day is exploited, EncryptHub deploys a sophisticated multi-staged attack.<\/p>\n<p>First, it installs the Rhadamanthys backdoor Trojan, granting the threat actor full access and control over the victim&#8217;s system.<\/p>\n<p>The backdoor provides a portal for the secondary payload, the StealC malware.<\/p>\n<p>As a powerful information stealer, StealC is designed to extract essential data such as login passwords, credit card details, and other valuable personal information.<\/p>\n<p><strong>Technical Analysis<\/strong><\/p>\n<p>The exploit starts by delivering a .msc file that carries a malicious DLL.<\/p>\n<p>When opened, the .msc file calls the DLL using the MUIPath vulnerability.<\/p>\n<p>A call-back is initiated to the C&#038;C server, and it responds with an encoded payload.<\/p>\n<p>This payload contains the Rhadamanthys(sometimes leveraging XOR encoding) that persistently executes on successful deployment.<\/p>\n<p>Once Rhadamanthys is installed, it opens the gates for StealC, providing the ability to mine vital information such as saved passwords, internet browsing history, e-payment information, and more.<\/p>\n<p><strong>Mitigations<\/strong><\/p>\n<p>The zero-day is already patched in the Microsoft&#8217;s recent update CVE-2021-40444.<\/p>\n<p>It is advised that all Windows users immediately apply this security patch to diminish vulnerability to the exploit.<\/p>\n<p>Cybersecurity professionals also recommend maintaining robust and updated security software.<\/p>\n<p>Regular investment in cybersecurity training can further enhance a user&#8217;s natural vigilance against phishing attempts and suspicious links.<\/p>\n<p><strong>Conclusions<\/strong><\/p>\n<p>The use of Windows&#8217; zero-day flaws shows the need for constant vigilance and timely updates in the digital ecosystem.<\/p>\n<p>It is a strong reminder to each organization about maintaining robust security posture.<\/p>\n<p>Despite the rapid response of Microsoft in patching the vulnerability, this incident underlines the unending cat-and-mouse game between cybersecurity professionals and threat actors in cyber warfare.<\/p>\n<p><strong>Follow-Up Reading:<\/strong><\/p>\n<p><a href='https:\/\/www.infosecurity-magazine.com'>Infosecurity Magazine \u2013 Latest Cybersecurity News<\/a><\/p>\n<p><a href='https:\/\/www.darkreading.com\/'>Dark Reading &#8211; Cybersecurity Threat News<\/a><\/p>\n<p><a href='https:\/\/krebsonsecurity.com\/'>Krebs on Security \u2013 In-depth security news and investigation<\/a><\/p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8221; said one senior cybersecurity researcher. Body: Cybersecurity professionals have detected a new campaign by<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"pmpro_default_level":"","_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[2,5],"tags":[],"class_list":["post-3024","post","type-post","status-publish","format-standard","hentry","category-cybersecurity","category-news","pmpro-has-access"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/posts\/3024","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/comments?post=3024"}],"version-history":[{"count":1,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/posts\/3024\/revisions"}],"predecessor-version":[{"id":3032,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/posts\/3024\/revisions\/3032"}],"wp:attachment":[{"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/media?parent=3024"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/categories?post=3024"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/tags?post=3024"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}