Rhadamanthys Stealer Module Launch Via Rundll32.EXE — Detection Rule

Detects the use of Rundll32 to launch an NSIS module that serves as the main stealer capability of Rhadamanthys infostealer, as observed in reports and samples in early 2023

Read the full analysis on IntelFusions