Skip to content

Campaign record

Rhadamanthys in a fake update lure

Rhadamanthys delivered by a full-screen fake Windows Update lure

Status as last assessed
Active
First seen
2025-10-01
Last seen
2025-11-19
Indicators
21
Sources
1
Targets
Windows
  • Fake Windows Update screen
  • Rhadamanthys

Original research

This page summarises and structures that research; it is not a substitute for the original.

Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.

Summary

From the start of October, Huntress recorded a second lure feeding the same steganographic loader. Here the browser was pushed into full screen and dressed up as the blue update splash, animations included, before the viewer was asked to open the Run box and paste a line already sitting on the clipboard. The page source was not obfuscated, carried Russian comments, and posted each interaction to a statistics script, which gave Huntress a urlscan pivot for finding more sites. Five partner incidents between 1 and 17 October used one address for both the mshta stage and the PowerShell behind it, with only the filename rotating; the operator later moved the second-stage domain but kept the address. The payload at the end was Rhadamanthys, not Lumma. A takedown of Rhadamanthys infrastructure was announced on 13 November, yet more sites still served the lure on 19 November.

What changed since publication

The accounts above describe these indicators as they were on the day each was written. We re-check them ourselves and record every check, including the ones that find nothing — which is the only reason the gaps below can be stated rather than hidden.

Indicators checked
1 of 21
Checks recorded
2
Checks since publication
2
Never checked
20

Observation window 2026-08-10 to 2026-08-22. Checks are sampled, not continuous; the sampling policy is on /methodology. 20 indicators have never been checked by us at all.

Current recorded state

  • 1 Unregistered
  • 20 Not checked by us

Nothing has changed state between our first check and our most recent one. A domain that still resolves is not necessarily still serving anything — registrar hold pages answer DNS indefinitely, which is why the state above distinguishes “parked or suspended” from “resolving”.

Execution mechanisms

How the pasted command actually ran, as the published accounts describe it. Every row under “Mechanism” is one this campaign records; “Across the corpus” is the share of the 44 published campaigns in this corpus that record the same one — a baseline we can only state because we hold the whole set.

Execution mechanisms recorded for this campaign, with their frequency across the corpus
MechanismAcross the corpusATT&CK
Windows Run dialog23 of 4452%T1204.004
PowerShell19 of 4443%T1059.001
Clipboard injection15 of 4434%T1204.004
mshta.exe7 of 4416%T1218.005
PNG pixel-data steganography loader2 of 445%T1027.003

All 5 of these mechanisms appear together in 2 of the 44 campaigns on record, this one included. We record a mechanism only where a source describes one: an absent mechanism means nobody wrote it down, not that it did not happen.

Indicators

21 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator.

Indicators recorded for this campaign, shown defanged
IndicatorTypeRoleAssessmentFirst seenLast seenStateReport an error
domain, shown defanged for safety: cmevents dot livedomainLure pageNot yet assessed2025-11-19Not checked by usReport an error in domain record 82fb025d-718f-4458-a1b2-4453f43afa60
domain, shown defanged for safety: cmevents dot prodomainLure pageNot yet assessed2025-11-19Not checked by usReport an error in domain record 872e6035-6746-42c6-ac4c-aed625994e9c
domain, shown defanged for safety: cosmicpharma-bd dot comdomainLure pageNot yet assessed2025-11-19Not checked by usReport an error in domain record 890e39fc-e4a5-4984-bb02-143a8a91c5e3
domain, shown defanged for safety: galaxyswapper dot prodomainLure pageNot yet assessed2025-10-01Not checked by usReport an error in domain record e158c166-df8c-480b-954e-99b477a587da
domain, shown defanged for safety: groupewadesecurity dot comdomainLure pageNot yet assessed2025-11-19Not checked by usReport an error in domain record 98d083d0-ea23-4838-9f6c-7a7f84301ce5
domain, shown defanged for safety: sportsstories dot grdomainLure pageNot yet assessed2025-11-19Not checked by usReport an error in domain record b70cab2a-72b4-403d-8575-96132eaaf73a
domain, shown defanged for safety: virhtechgmbh dot comdomainLure pageNot yet assessed2025-11-19Not checked by usReport an error in domain record 621a6ef6-8907-425a-8ba8-368463635cf4
domain, shown defanged for safety: xcvcxoipoeww dot sitedomainLure pageAttacker-controlled2025-10-012025-10-05Unregistered2026-08-22Report an error in domain record 30482b2e-ec0d-4d19-bafc-70eb4cb43a51
domain, shown defanged for safety: xmcniiadpwqw dot sitedomainLure pageAttacker-controlled2025-10-01Not checked by usReport an error in domain record 7616a26f-52c6-4a28-981c-28123de1637f
domain, shown defanged for safety: xpoalswwkjddsljsy dot comdomainLure pageAttacker-controlled2025-10-01Not checked by usReport an error in domain record e5211c6b-235e-4bae-8c9e-9096f23f2846
ip, shown defanged for safety: 192 dot 124 dot 176 dot 103ipLure pageNot yet assessed2025-10-012025-10-05Not checked by usReport an error in ip record 02ea5ddf-7480-446e-8f3a-e85ca5713835
url, shown defanged for safety: hxxp colon slash slash 141 dot 98 dot 80 dot 175/ercx dot daturlDownload URLNot yet assessed2025-10-132025-10-13Not checked by usReport an error in url record c6638fb6-b31c-4aa4-a665-496cbb4b9b6c
url, shown defanged for safety: hxxp colon slash slash 141 dot 98 dot 80 dot 175/gpsc dot daturlDownload URLNot yet assessed2025-10-052025-10-05Not checked by usReport an error in url record 00f3d9a9-1de1-43d8-aea4-6bcd6b0f9184
url, shown defanged for safety: hxxp colon slash slash 141 dot 98 dot 80 dot 175/one dot daturlDownload URLNot yet assessed2025-10-172025-10-17Not checked by usReport an error in url record fb3dcab1-e468-42e6-ad02-9f4ca4c53798
url, shown defanged for safety: hxxp colon slash slash 141 dot 98 dot 80 dot 175/rtdx dot daturlDownload URLNot yet assessed2025-10-152025-10-15Not checked by usReport an error in url record 9e82b57d-b07c-41d5-8bfa-31cd7b1eaf67
url, shown defanged for safety: hxxp colon slash slash 141 dot 98 dot 80 dot 175/tick dot oddurlDownload URLNot yet assessed2025-10-012025-10-01Not checked by usReport an error in url record d2726500-6f9e-4114-a6c4-6335c63dd57e
url, shown defanged for safety: hxxp colon slash slash 141 dot 98 dot 80 dot 175/very dot daturlDownload URLNot yet assessed2025-10-01Not checked by usReport an error in url record 2df73606-2823-4eae-9d90-92dd04e25d74
ip, shown defanged for safety: 141 dot 98 dot 80 dot 175ipPayload hostNot yet assessed2025-10-012025-10-17Not checked by usReport an error in ip record 75c16d4c-8f04-4be6-b004-027f681a7e61
ip, shown defanged for safety: 94 dot 74 dot 164 dot 136ipPayload hostNot yet assessedNot checked by usReport an error in ip record 5894588f-185a-47a9-bde6-8a6e31382ca6
domain, shown defanged for safety: securitysettings dot livedomainStagingAttacker-controlled2025-10-012025-10-05Not checked by usReport an error in domain record 3da59590-4bc2-4f3e-8621-7df44b0cace8
domain, shown defanged for safety: xoiiasdpsdoasdpojas dot comdomainStagingAttacker-controlled2025-10-132025-10-17Not checked by usReport an error in domain record 0bf1cc92-a94b-4ea4-a082-264a82dabdb2

“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.

Not on this record

This record does not yet carry a second publisher's account or any overlap with another campaign in this corpus. Each appears on this page as its own section once it exists; none of it is inferred.

Cite as

ClickFixReport, “Rhadamanthys in a fake update lure”, campaign ID 018c699e, retrieved 2026-08-07, snapshot fb0eed7.

https://clickfixreport.com/campaigns/018c699e/rhadamanthys-fake-windows-update-clickfix

Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.