Unwanted Christmas Gift: Medical-themed Information Stealer Malware
During Open-Source investigations, Just Protect observed an information-stealing malware variant masquerading as medical software uploaded to various public malware repositories in mid-late December 2024. Notably, the file used a medical-themed lure by leveraging the name medicalanalysispro.exe. Further analysis of the file indicated that the malware likely belongs to the Rhadamanthys family and likely leveraged PureCrypter as the loader.
Given the medical theming of the lure, it is possible that the delivery URL hxxp://77.238.245[.]43/tamus/medicalanalysispro.zip was distributed via phishing emails to a set of healthcare/medical targets. In such a scenario, the archive file medicalanalysispro.zip would be downloaded after the victim user visits the URL. Following this, the user would have to manually extract and run the associated executable, which is a PureCrypter loader. From here, the Rhadamanthys information stealer would then be loaded.
Given this requirement for multiple user interaction steps, this malware and the associated delivery mechanism are relatively unsophisticated. However, an unsuspecting user could be convinced or instructed to run the associated file if delivered via a tailored spearphishing email, especially if the end-user is under time pressure, which is undoubtedly true for many modern healthcare professionals.
Concerningly, information-stealing malware variants such as Rhadamanthys have the potential to impact healthcare organisations via the theft of confidential information, including private patient data. This data can subsequently be sold on the dark web, leading to patient identity theft, reputational damage and possibly regulatory/compliance issues.
Just Protect is not currently aware of any victims associated with this malware nor the geographical scope of targeting. However, given the medically themed nature of the lure, it is likely that this malware was used to target entities within the healthcare space. Consequently, this is a stark reminder that cybercriminals often ramp up their operations as many healthcare businesses are winding down for the holiday period.
Recommendations:
Just Protect recommends that healthcare organisations adopt a multi-layered approach to cybersecurity, including but not limited to:
- Conduct Security Awareness training to help employees identify phishing emails and social engineering attacks.
- Leverage an anti-phishing email security solution.
- Ensure robust endpoint security measures to detect and prevent the execution of malware such as Rhadamanthys.
Indicators of Compromise:
| IOC | Details |
| C196CE2452FE376F2AD783B44B3CBC2F72E9457250E0DE4F95CDFB70440FD1E6 | medicalanalysispro.zip |
| 357829B06C1C185E44EFA729DD8671487A43778A3BE1B6F46C7956F4D4CB49E2 | medicalanalysispro.exe |
| 8E2EC352E0EC1212011FEFD1ABE73FCBBCE42BEC907525922BA7C64EAF26BA24 | medicalanalysis_1.exe |
| hxxp://77.238.245[.]43/tamus/medicalanalysispro.zip | Delivery URL |
| 77.238.245[.]43 | Delivery IP |
| erdogansigorta[.]com | Possible C2 (unconfirmed) |
