RedLine is a financially motivated cybercriminal malware operation centered on an information-stealing malware family widely used to harvest credentials and other sensitive data from compromised systems. The malware is known for stealing passwords, browser cookies, payment card data, and cryptocurrency wallet information, and has been distributed through social-engineering lures and fake software installers. Observed delivery methods include impersonation of legitimate software and operating system upgrade workflows to trick users into executing staged payloads. Operationally, RedLine campaigns have used multi-stage infection chains involving script interpreters and command shells to retrieve and execute additional payloads, with obfuscation techniques intended to hinder detection and analysis. Reported tradecraft includes remotely fetching disguised payloads, reversing payload content to complicate inspection, and establishing command-and-control communications to receive tasking after compromise. These behaviors support credential theft, session hijacking through browser cookie theft, initial access via user execution, defense evasion, and post-exploitation data collection and exfiltration. RedLine has been associated with criminal infrastructure significant enough to attract coordinated law-enforcement disruption, including action against infrastructure tied to RedLine and the related META infostealer. Public reporting has also linked Maxim Rudometov to the creation of the RedLine infostealer. The actor or operators behind RedLine are best characterized as cybercriminals focused on information theft rather than a nation-state espionage group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Distributed via fake Windows 11 upgrade installers hosted on a spoofed Microsoft-themed site to steal passwords, browser cookies, credit card data, and cryptocurrency wallet information from victims.
Infostealer malware used for credential theft and data exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.