Copyright-Themed Phishing Lures Target Europe



phishing websiteA phishing campaign is targeting European countries with lures themed around copyright infringement, researchers at Cybereason warn.

The phishing emails are designed to deliver the Rhadamanthys infostealer malware.

“These campaigns often involve emails impersonating companies and their legal departments, falsely claiming recipients have violated copyright on social media or elsewhere and demanding content removal,” the researchers write.

“The emails typically contain malicious download links leading to archives hosted on services like Dropbox, Discord, or as in the current campaign - Mediafire through hosted redirects via newly registered domains.”

The campaign is opportunistically targeting entities across Europe as well as Israel, with a focus on Central and Eastern Europe.

“Since the beginning of April 2025, Cybereason has observed the same copyright infringement lures against the following European countries: Albania, Austria, Bulgaria, Germany, Greece, Hungary, Ireland, Israel, Italy, Poland, Portugal, Romania, Slovakia, Slovenia, Spain and the United Kingdom; however, more countries may be targeted in subsequent campaign waves,” the researchers write.

Stealthy malware like Rhadamanthys is frequently used to gather information or gain access to assist in future attacks, often involving ransomware or data-theft extortion.

“These campaigns leverage fear-based, highly localized phishing emails with region-specific language to increase credibility and user engagement,” Cybereason says. “Threat actors employ various techniques to evade detection, including code obfuscation, shellcode encryption, hiding malicious code in resource data, and expanding file sizes.

Persistence mechanisms often involve modifying Windows Registry Run keys. The use of similar phishing infrastructure and delivery mechanisms across campaigns distributing different malware families suggests shared tooling, a possible affiliate model, or coordinated activity among related threat groups.”

New-school security awareness training can give your organization an essential layer of defense against social engineering attacks. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

Cybereason has the story.


Will your users respond to phishing emails?

KnowBe4's Phishing Reply Test (PRT) is a complimentary IT security tool that makes it easy for you to check to see if key users in your organization will reply to a highly targeted phishing attack without clicking on a link. PRT will give you quick insights into how many users will take the bait so you can take action to train your users and better protect your organization from these fraudulent attacks!

PRT-imageHere's how it works:

  • Immediately start your test with your choice of three phishing email reply scenarios
  • Spoof a Sender’s name and email address your users know and trust
  • Phishes for user replies and returns the results to you within minutes
  • Get a PDF emailed to you within 24 hours with the percentage of users that replied

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-reply-test



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews