RadThief
RadThief is an infostealer malware family referenced as being delivered in multiple intrusion and malware distribution campaigns. The content states that Handala, also tracked as Void Manticore and Storm-842, is known to deploy RadThief stealer malware during its attacks; one source further notes it as 'Radthief (aka: Rhadamanthys)'. Handala is described as a pro-Palestinian, pro-Iran-aligned actor associated with destructive hack-and-leak operations, primarily targeting Israeli-linked organizations and also claiming activity against organizations in Israel, Jordan, Saudi Arabia, and a Western medical technology company. Handala commonly gains initial access through social engineering and phishing, including impersonation of legitimate organizations. Separately, Google Threat Intelligence Group reporting cited in the content says financially motivated group UNC5142 distributes RadThief alongside Vidar and Lummac.V2 via compromised WordPress sites. In those campaigns, UNC5142 injects JavaScript downloaders called ClearShort into vulnerable WordPress sites, uses BNB Smart Chain smart contracts as a control layer as part of the EtherHiding technique, hosts malicious pages on Cloudflare pages.dev, and uses fake Cloudflare verification and Chrome update prompts as lures. By mid-2025, about 14,000 websites reportedly showed traces of UNC5142's injected scripts. High-confidence behavioral detail in the provided content is limited to RadThief being an infostealer/stealer malware used in phishing, social-engineering, and web-based lure delivery chains; no specific standalone technical indicators or RadThief-specific capabilities beyond credential/data theft are directly provided.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Handala is known to deploy the Hatef wiper malware as well as the Radthief (aka: Rhadamanthys) stealer malware during its attacks.
Techniques & procedures
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
1 technique
Initial Access
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A stealer malware used by Handala during attacks to steal data and support hack-and-leak operations.
Infostealer malware used by UNC5142, delivered through blockchain-based infrastructure to steal credentials and sensitive information.
Infostealer malware used by UNC5142, delivered through blockchain-based infrastructure to steal credentials and sensitive information.
Information stealer malware used to exfiltrate credentials and sensitive data, often as part of Sandworm's hybrid operations.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.