Alpha Cyber

Graphing Rhadamanthys bonus-mirror.com Phishing Domain: Deep Infrastructure Mapping to Protect Your Organization

Phishing attacks continue to be one of the most effective and damaging methods used by cybercriminals to infiltrate organizations worldwide.

Alpha Cyber Research2 min readupdated 1 Apr 2026
rhadamanthys stealer promoting image

Phishing attacks continue to be one of the most effective and damaging methods used by cybercriminals to infiltrate organizations worldwide. Recent campaigns linked to the threat group Rhadamanthys highlight the increasing sophistication of phishing infrastructures that are designed not only to steal credentials but also to deploy malicious payloads under the radar.

One key domain in this ecosystem is bonus-mirror.com, which serves as a critical component in the attacker’s web of operations. Understanding and mapping the infrastructure behind this domain can offer invaluable insight into how these attackers orchestrate their campaigns and how your organization can defend against them.

The Rhadamanthys Phishing Infrastructure: What We’ve Discovered

Rhadamanthys bonus-mirror.com Graph

Through extensive infrastructure mapping, we identified several interconnected domains and URLs that work in concert to support phishing and malware distribution activities.

These components include:

Phishing domains used to impersonate legitimate services and trick users into divulging sensitive information.
Malicious URLs that host malware payloads and command-and-control scripts.
Multiple related domains that help attackers maintain resilience by quickly shifting infrastructure when detected.

This networked approach allows the attackers to maintain persistence, avoid detection, and extend the lifespan of their campaigns.

Why Infrastructure Mapping is Essential

Traditional security solutions often focus on blocking individual IPs or URLs reactively. However, infrastructure mapping enables cybersecurity teams to visualize the full attack surface linking domains, URLs, IP addresses, and other indicators into a comprehensive picture of attacker operations.

With infrastructure mapping, organizations can:

Preemptively block related malicious domains and URLs, stopping attackers from gaining a foothold.
Detect infrastructure reuse patterns that indicate ongoing or evolving campaigns.
Enhance threat hunting capabilities by understanding attacker TTPs (tactics, techniques, and procedures).
Respond faster and more effectively to active attacks by disrupting communication channels.

Key Indicators of Compromise (IOCs) to Block

TypeIndicator
URLhttp://77.239.96.51/rh_0.9.0.exe
URLhttps://ypp-studio.com
URLhttps://ypp-studio.com/update.txt
URLhttps://ypp-studio.com/update.xn--txt;iex-926c
Domainypp-studio.com
Domainanimacionbodas.com
Domainaward2x.org
Domainbonus-mirror.com
Domainbonus-mirror.info
Domainbonus-mirror.org

How Blocking These IOCs Helps

By blocking these domains and URLs:

  • You prevent users from accessing phishing pages designed to harvest credentials.
  • You stop malware downloads and command-and-control communications from succeeding.
  • You reduce your exposure to lateral movement within your network.
  • You disrupt the attacker’s ability to pivot and maintain persistence.

The Importance of Continuous Threat Intelligence and Monitoring

Phishing infrastructures are rarely static. Attackers continuously adjust domains, IP addresses, and payload delivery methods to evade detection. That’s why continuous infrastructure mapping combined with real-time threat intelligence feeds is critical.

Security teams need proactive solutions that adapt as attackers evolve, identifying new malicious assets as soon as they appear and updating blocklists and detection rules accordingly.

Partner with Experts to Stay One Step Ahead

At Alpha Cyber, we specialize in advanced infrastructure mapping and real-time threat intelligence tailored to your organization’s unique risk profile. Our services provide:

  • Continuous monitoring of attacker infrastructure
  • Rapid identification of emerging phishing and malware campaigns
  • Strategic IOC management and enforcement
  • Customized threat hunting and incident response

Don’t Wait Until It’s Too Late

Phishing attacks leveraging infrastructure like bonus-mirror.com pose a clear and present danger. Protect your organization with proactive infrastructure mapping and IOC management strategies.

Secure your business today contact us to learn how

If you want, we can help tailor this content for email newsletters, social media awareness posts, or internal training materials to maximize your security posture.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]