Skip to main content
Mallory
MalwareRansomwareUsed by 8 actorsExploits 1 CVE

RedLine

Also known asRedLine Stealer

RedLine Stealer is a commodity infostealer/password-stealing malware family, also referred to as RedLine or RedLine password stealer, that has been widely used since at least 2020 and is commonly sold in the cybercriminal economy as MaaS. It is repeatedly described as inexpensive, easy to use, and highly popular, and has been observed alongside other stealers such as Lumma, Vidar, Raccoon, RisePro, MetaStealer, Rhadamanthys, and Stealc.

Its core capability is credential theft. The content explicitly states that RedLine steals passwords and session tokens, extracts and exfiltrates browser cookies, and targets browser-stored credentials. It is described as capable of stealing credentials from browser password stores and browser data, and is associated with theft of system information, cookies, session tokens, and cryptocurrency wallet data. Microsoft also classifies RedLine as cryware in some contexts because it targets non-custodial cryptocurrency hot-wallet data. The content further notes that RedLine has sent victim data to its C2 or RedLine panel server, has used Base64 to encode command-and-control traffic, includes an anti-sandbox technique that requires successful C2 communication to continue execution, and has been observed abusing legitimate web services as C2 infrastructure. Splunk reporting cited in the content also states that RedLine can modify registry keys and disable Windows Update-related services on compromised hosts.

Observed delivery vectors in the content include phishing emails with malicious attachments, phishing messages, malicious installers, spoofed update prompts, ZIP bundles, cracked software/warez, YouTube videos, watering-hole sites, Discord CDN-hosted payload delivery, and LNK-based phishing chains. One report states RedLine was bundled in a ZIP file with other software; another notes it was delivered immediately after users downloaded a malicious installer or responded to a spoofed update prompt. Group-IB reporting cited in the content says RedLine was used in campaigns spread via fake websites, malicious links in game reviews and social-media lotteries, file-sharing sites, and compromised social-media accounts.

RedLine is linked in the content to multiple threat actors and intrusion sets. Microsoft states DEV-0537/LAPSUS$ used the RedLine password stealer to obtain passwords and session tokens, and other reporting on the Uber incident similarly notes Lapsus$ is known to use RedLine-stolen credentials. The content also says credentials stolen by RedLine were leveraged in identity-centric intrusions, including Snowflake-related compromises attributed to UNC5537, where infostealer-obtained credentials were used in environments lacking enforced MFA. Kaspersky reporting cited in the content says a separate threat group targeting Russian organizations previously used RedLine, alongside PureRAT and Cobalt Strike, before later adopting Ravage.

Targeting described in the content is broad and opportunistic, affecting consumers and enterprises. Examples include theft of FIFA-related credentials and web addresses in World Cup-themed fraud ecosystems, compromise of accounts such as PayPal, Amazon, Steam, Roblox, and Epic Games, and use against Russian educational institutions, energy companies, financial organizations, government bodies, and diplomatic institutions when deployed by specific actors. The content also notes RedLine’s role in large-scale credential theft operations run by Russian-speaking cybercriminal groups, with more than 890,000 infected devices worldwide in one 2022 campaign.

High-confidence infrastructure and indicators mentioned in the content are limited. The content explicitly notes Base64-encoded C2 traffic, exfiltration to a RedLine C2/panel server, and use in Discord CDN-delivered malware chains. No single canonical RedLine hash or stable C2 IOC is provided in the source material.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2024-43451Windows NTLM Hash Disclosure via Malicious .url FileExploited in the wild

ClearSky Cyber Security has uncovered a new zero-day vulnerability, CVE-2024-43451, actively exploited in the wild, targeting Windows systems primarily in Ukraine. This flaw enables attackers to exploit URL files for malicious activity by performing actions as simple as a single right-click.

via security online infosecurityonline.info
THREAT ACTORS

Groups observed using it

8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
LAPSUS$

Deploying the malicious Redline password stealer to obtain passwords and session tokens ... Redline password stealer has become the malware of choice for stealing credentials and is commonly distributed through phishing emails, watering holes, warez sites, and YouTube videos.

via bleeping computerbleepingcomputer.com
Amadey

Amadey is a modular Windows botnet sold as MaaS by author "InCrease" on XSS/Exploit forums, active since 2018. It commonly drops Lumma, StealC, RedLine, CoinMiners, and RATs.

via breakglass intelintel.breakglass.tech
UAC-0194

ClearSky researchers observed that this vulnerability has been used to distribute various malware, including Redline Stealer and SparkRAT.

via security online infosecurityonline.info
YouTube Ghost Network

Others include StealC, RedLine, Odebug and other Phemedrone variants, and NodeJS loaders and downloaders.

via dark readingdarkreading.com
Zestix

Hudson Rock researchers investigated the alleged breaches and found the threat actor relied on distributing infostealers such as RedLine, Lumma, or Vidar... to harvest credentials.

via dark readingdarkreading.com
Void Blizzard

"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."

via recorded future blogrecordedfuture.com
Storm-0501

"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."

via recorded future blogrecordedfuture.com
Curious Serpens

"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."

via recorded future blogrecordedfuture.com
MITRE ATT&CK

Techniques & procedures

29 distinct techniques documented for this family, organized by ATT&CK tactic.

T1583.008MalvertisingEvidence1

The malware can be hidden in legitimate-looking mobile apps, on web pages, in malicious ads, and phishing links/attachments, among other places.

T1586Compromise AccountsEvidence1

Selon Group-IB, les cybercriminels s’appuient également sur ... la prise de contrôle de médias sociaux pour disséminer les logiciels malveillants.

T1608.006SEO PoisoningEvidence1

A combined 35% of social engineering cases involved less conventional methods, including SEO poisoning and malvertising, smishing and MFA bombing.

Initial Access

4 techniques
T1078Valid AccountsEvidence5

В ноябре 2023 года APT29 (Midnight Blizzard) залезли в корпоративную среду Microsoft через password spraying единственного тестового облачного tenant без MFA... Initial Access и Credential Theft (T1078, T1621)... Valid Accounts (T1078...)

T1189Drive-by CompromiseEvidence2

One example is ClickFix, a technique using fake browser alerts, fraudulent update prompts and drive-by downloads to initiate compromise.

T1566PhishingEvidence3

Для первоначального проникновения злоумышленники рассылают фишинговые письма на корпоративные адреса. Вложения маскируются под документы Microsoft Excel: списки товаров, формы для заполнения и другие рабочие файлы.

T1566.001Spearphishing AttachmentEvidence2

В 2026 году атаки начинались через фишинговое письмо с ZIP-архивом, содержащим XLL-файл. Этот файл маскировался под легитимную надстройку для Microsoft Excel.

Execution

4 techniques
T1053.005Scheduled TaskEvidence3

During Frankenstein, the threat actors ran a command script to set up persistence as a scheduled task named "WinUpdate". MultiLayer Wiper uses a batch script launched via a scheduled task to delete Windows Event Logs. Tarrask may abuse the Windows schtasks command-line tool to create "hidden" scheduled tasks.

T1059.003Windows Command ShellEvidence2
TacticExecution

During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.

T1204User ExecutionEvidence1
TacticExecution

Expect to see typosquatted FIFA domains, malicious mobile applications, infostealers sold on Telegram

T1204.002Malicious FileEvidence2
TacticExecution

Двойной клик по нему запускал приложение Excel, которое загружало в свой процесс исполняемую DLL-библиотеку, что приводило к запуску вредоносного кода.

Persistence

3 techniques
T1053.005Scheduled TaskEvidence3

During Frankenstein, the threat actors ran a command script to set up persistence as a scheduled task named "WinUpdate". MultiLayer Wiper uses a batch script launched via a scheduled task to delete Windows Event Logs. Tarrask may abuse the Windows schtasks command-line tool to create "hidden" scheduled tasks.

T1078Valid AccountsEvidence5

В ноябре 2023 года APT29 (Midnight Blizzard) залезли в корпоративную среду Microsoft через password spraying единственного тестового облачного tenant без MFA... Initial Access и Credential Theft (T1078, T1621)... Valid Accounts (T1078...)

T1205Traffic SignalingEvidence1

RedLine Stealer has an anti-sandbox technique that requires the malware to consistently check with the C2 server, if the communication fails RedLine Stealer will not continue execution.

T1053.005Scheduled TaskEvidence3

During Frankenstein, the threat actors ran a command script to set up persistence as a scheduled task named "WinUpdate". MultiLayer Wiper uses a batch script launched via a scheduled task to delete Windows Event Logs. Tarrask may abuse the Windows schtasks command-line tool to create "hidden" scheduled tasks.

T1078Valid AccountsEvidence5

В ноябре 2023 года APT29 (Midnight Blizzard) залезли в корпоративную среду Microsoft через password spraying единственного тестового облачного tenant без MFA... Initial Access и Credential Theft (T1078, T1621)... Valid Accounts (T1078...)

Stealth

5 techniques
T1027Obfuscated Files or InformationEvidence1
TacticStealth

The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.

T1036MasqueradingEvidence1
TacticStealth

Des sites usurpant le nom d’entreprises connues ... pour convaincre les victimes de télécharger des fichiers malveillants.

T1078Valid AccountsEvidence5

В ноябре 2023 года APT29 (Midnight Blizzard) залезли в корпоративную среду Microsoft через password spraying единственного тестового облачного tenant без MFA... Initial Access и Credential Theft (T1078, T1621)... Valid Accounts (T1078...)

T1140Deobfuscate/Decode Files or InformationEvidence1
TacticStealth

The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'

T1205Traffic SignalingEvidence1

RedLine Stealer has an anti-sandbox technique that requires the malware to consistently check with the C2 server, if the communication fails RedLine Stealer will not continue execution.

Credential Access

7 techniques
T1003OS Credential DumpingEvidence1

Credential-harvesting malware is the most common first-stage payload... configured to extract browser-stored credentials, saved tokens and session cookies.

T1110.004Credential StuffingEvidence1

the vast pool of compromised user accounts heightens the risk of credential stuffing and potential large-scale data breaches

T1528Steal Application Access TokenEvidence1

Fortinet found hundreds of thousands of user logins, plus more than 4,600 FIFA web addresses, in data swept up by credential-stealing malware like Vidar, LummaC2, and RedLine.

T1539Steal Web Session CookieEvidence3

These tools are configured to extract browser-stored credentials, saved tokens and session cookies.

T1555Credentials from Password StoresEvidence3

Operation MidnightEclipse stole saved cookies and login data from targeted systems; IceApple can collect files, passwords, and other data from a compromised host; RedLine Stealer collected chat logs and files associated with chat services.

T1555.003Credentials from Web BrowsersEvidence1

The content repeatedly describes threat actors and malware stealing usernames, passwords, cookies, session tokens, and other saved credentials from web browsers such as Chrome, Firefox, Internet Explorer, Edge, Opera, Safari, and Yandex.

T1649Steal or Forge Authentication CertificatesEvidence2

The detection of multiple stealer malware families, particularly the dominance of RedLine and Lumma... RedLine is known for its capabilities in credential stealing

Discovery

1 technique
T1082System Information DiscoveryEvidence1
TacticDiscovery

The content repeatedly describes malware and threat actors collecting host details such as OS version, hostname, architecture, CPU, memory, BIOS, domain, language, and other configuration data; e.g., "APT41 uses multiple built-in commands such as systeminfo and net config Workstation to enumerate victim system basic configuration information."

Lateral Movement

1 technique
T1550Use Alternate Authentication MaterialEvidence1

A “pass-the-cookie” attack is a type of attack where an attacker can bypass authentication controls by compromising browser cookies... “Pass-the-cookie” is like pass-the-hash or pass-the-ticket attacks in Active Directory.

Collection

1 technique
T1005Data from Local SystemEvidence2

The content repeatedly describes threat actors and malware collecting, stealing, identifying, copying, or staging files, documents, credentials, logs, databases, and other information from compromised hosts or local systems.

T1071.001Web ProtocolsEvidence2

The content repeatedly describes threat actors, malware, and campaigns using HTTP and/or HTTPS for command and control, including examples such as BlackEnergy communicating with C2 over HTTP POST requests and many other families using HTTP/S for C2.

T1105Ingress Tool TransferEvidence1

Это простейший загрузчик: он скачивает и запускает два исполняемых файла по вшитым в него URL.

T1132Data EncodingEvidence2

C2 traffic from ADVSTORESHELL is encrypted, then encoded with Base64 encoding... APT19 HTTP malware variant used Base64 to encode communications to the C2 server... APT33 has used base64 to encode command and control traffic.

T1205Traffic SignalingEvidence1

RedLine Stealer has an anti-sandbox technique that requires the malware to consistently check with the C2 server, if the communication fails RedLine Stealer will not continue execution.

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence2

ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.

INDICATORS OF COMPROMISE

IOCs tracked for this family

136 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
89 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
37 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
10 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
ip.v4●●●●●●●●●●●●View more in apptoday
ip.v4●●●●●●●●●●●●View more in apptoday
domain●●●●●●●●●●●●View more in apptoday
ip.v4●●●●●●●●●●●●View more in apptoday
domain●●●●●●●●●●●●View more in app7 days ago
hash.md5●●●●●●●●●●●●View more in app7 days ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching136

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution8

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping29

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.