RedLine Stealer is a .NET-based Windows information stealer that emerged in 2020 and has been sold under a malware-as-a-service model. It is distributed through phishing email, malicious websites impersonating legitimate software, social-engineering lures, and cracked software or games. RedLine collects host profiling data, including system, hardware, software, security-product, process, language, and network-related information. It steals browser-stored passwords, cookies, autofill and payment-card data; cryptocurrency-wallet data; and credentials or session data associated with communication, gaming, file-transfer, messaging, and VPN applications. Theft of browser cookies enables hijacking of authenticated web sessions, including Claude sessions observed on infected Windows endpoints. RedLine can capture desktop screenshots and search for targeted local files, then serialize and exfiltrate collected data to command-and-control infrastructure. It also supports remote tasking to download and execute additional payloads, run shell commands, and open links. The malware employs runtime string construction and window hiding to hinder detection and analysis.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Microsoft created a security patch for Windows systems to fix the vulnerability, giving it the CVE identifier CVE-2024-43451. The security patch was published on November 12th, 2024. | The other files detected exploiting the new vulnerability followed a similar attack scenario that ended with the installation of Redline Stealer malware.
The embedded file with a randomized file name exploits a particular vulnerability —CVE-2017-11882—to execute malicious code to deliver and execute malware on a victim’s device. | Redline (also known as Redline Stealer) is a commercial malware family designed to collect sensitive information from infected devices, such as saved credentials, autocomplete data, credit card information, and more.
17 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Starting in mid-March 2022, eSentire observed an increase in the deployment of Redline Stealer malware. Redline Stealer is an information stealing malware that was first identified in early 2020.
2020 (or earlier): The Infection The campaign operator gets infected by RedLine Stealer. Admin credentials are exfiltrated to the Dark Web.
2020 (or earlier): The Infection The campaign operator gets infected by RedLine Stealer. Admin credentials are exfiltrated to the Dark Web.
In many cases, ZingoStealer also delivers additional malware such as RedLine Stealer and the XMRig cryptocurrency mining malware to victims.
Batloader has been observed to drop several malware payloads, such as Ursnif, Vidar, Bumbleloader, RedLine Stealer, ZLoader, Cobalt Strike, and SmokeLoader.
When KELA first observed the threat actor “_META_” offering a new stealer, it was marketed as having the same functionality and panel as RedLine Stealer.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
REDLINE uses a string obfuscation technique... METASTEALER ... employ[s] obfuscation methods, including obscuring the control flow... STEALC encrypts its strings using a combination of Base64 + RC4.
REDLINE [uses] malicious websites hosting seemingly legitimate applications... METASTEALER [was] encountered ... within a campaign masquerading as Roblox.
“The main payload... injects it into a subprocess. The payload itself stays in memory.”
REDLINE ... extracting ... cookies... STEALC [collects] Browser cookies.
REDLINE ... identifies and steals cryptocurrency wallets... STEALC [collects] Cryptocurrency wallets.
REDLINE collects essential system details such as UserName... STEALC collects Username / computername.
REDLINE ... monitors running processes... STEALC [collects] installed programs, running processes.
1,530 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information stealer mentioned as a prior example of malware distributed through gaming-software and cracked-game lures.
An information-stealing payload explicitly identified as delivered and process-injected by DarkTortilla.
Infostealer Windows utilisé dans la campagne décrite pour collecter des informations de connexion et détourner les sessions Claude afin d’utiliser les crédits des victimes.
Infostealer identified in the campaign that compromised Claude-platform login sessions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.