Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
MalwareUsed by 1 actor

RadThief

RadThief is an infostealer malware family referenced as being delivered in multiple intrusion and malware distribution campaigns. The content states that Handala, also tracked as Void Manticore and Storm-842, is known to deploy RadThief stealer malware during its attacks; one source further notes it as 'Radthief (aka: Rhadamanthys)'. Handala is described as a pro-Palestinian, pro-Iran-aligned actor associated with destructive hack-and-leak operations, primarily targeting Israeli-linked organizations and also claiming activity against organizations in Israel, Jordan, Saudi Arabia, and a Western medical technology company. Handala commonly gains initial access through social engineering and phishing, including impersonation of legitimate organizations. Separately, Google Threat Intelligence Group reporting cited in the content says financially motivated group UNC5142 distributes RadThief alongside Vidar and Lummac.V2 via compromised WordPress sites. In those campaigns, UNC5142 injects JavaScript downloaders called ClearShort into vulnerable WordPress sites, uses BNB Smart Chain smart contracts as a control layer as part of the EtherHiding technique, hosts malicious pages on Cloudflare pages.dev, and uses fake Cloudflare verification and Chrome update prompts as lures. By mid-2025, about 14,000 websites reportedly showed traces of UNC5142's injected scripts. High-confidence behavioral detail in the provided content is limited to RadThief being an infostealer/stealer malware used in phishing, social-engineering, and web-based lure delivery chains; no specific standalone technical indicators or RadThief-specific capabilities beyond credential/data theft are directly provided.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Handala

Handala is known to deploy the Hatef wiper malware as well as the Radthief (aka: Rhadamanthys) stealer malware during its attacks.

via industrialcyberindustrialcyber.co
MITRE ATT&CK

Techniques & procedures

2 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566PhishingEvidence1

Handala commonly gains Initial Access through social engineering via phishing using a combination of exploitation of major events and vulnerabilities and impersonation of legitimate organizations to steal and leak data through a dedicated leak site.

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence1

In this operation, over 200,000 systems, servers, and mobile devices have been wiped and 50 terabytes of critical data have been extracted.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping2

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.