RedLine Stealer is a Windows information-stealing malware family written in C# that emerged in early 2020 and became one of the most widely used commodity stealers in the cybercrime ecosystem. It is commonly sold and deployed as part of malware-as-a-service and pay-per-install operations, and has frequently appeared alongside other crimeware families such as loaders, stealers, miners, and proxy malware. RedLine has been used both for direct theft from individual victims and as an upstream access source for broader intrusions, including enterprise and cloud account compromise.
Its core functionality centers on theft of browser-saved credentials, session cookies, and other sensitive user data. Reported use cases include harvesting credentials later abused to access SaaS platforms, VPNs, cloud file-sharing services, and enterprise identities. RedLine has also been associated with collection of browser data, wallet-related information, and screenshots, making it relevant to both account takeover and financially motivated operations. Stolen session material can enable follow-on abuse without requiring password re-entry or MFA at the time of replay.
RedLine is regularly delivered through opportunistic social-engineering and malware distribution channels rather than bespoke exploitation. Observed delivery vectors include cracked software, fake installers, malicious email attachments, drive-by download chains, and broader bundled malware campaigns. It has also been observed as a payload delivered by third-party loaders and distribution services, including campaigns abusing remote management tooling or gaming-themed lures. In some operations, RedLine was one component of a larger infection set that also established persistence, weakened defenses, enabled proxying, or deployed additional payloads.
The malware has figured prominently in the stealer-log economy. Credentials and session artifacts harvested by RedLine have been resold in underground markets and subsequently used by initial access brokers and intrusion actors. Documented downstream abuse includes compromise of corporate accounts on cloud collaboration and file-sharing platforms and use of infostealer-derived access in larger extortion and intrusion workflows. RedLine also appeared in infrastructure and panel ecosystems hosted by abuse-tolerant providers and was significant enough to be referenced in major law-enforcement disruption efforts, including the dismantling of RedLine and META infrastructure in Operation Magnus in October 2024.
Operationally, sandboxed samples attributed to RedLine have shown host discovery behavior, process enumeration, registry querying, dropped components, and suspicious memory-manipulation or injection-related activity, consistent with stealer execution chains that stage or protect payloads before exfiltration. RedLine has also been observed in campaigns linked to Russian-speaking cybercrime ecosystems and bundled operations such as Operation STANDOFF, where it contributed credential theft within a broader monetization chain.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ClearSky Cyber Security has uncovered a new zero-day vulnerability, CVE-2024-43451, actively exploited in the wild, targeting Windows systems primarily in Ukraine. This flaw enables attackers to exploit URL files for malicious activity by performing actions as simple as a single right-click.
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : RedLine Stealer (vol de credentials, MissionID @Tui , C2 : 185.215.113.44:23759 )
The RedLine Stealer Trojan is used to spread a malware called Bobik.
LAPSUS$ acquired and used the Redline password stealer in their operations.
Amadey is a modular Windows botnet sold as MaaS by author "InCrease" on XSS/Exploit forums, active since 2018. It commonly drops Lumma, StealC, RedLine, CoinMiners, and RATs.
ClearSky researchers observed that this vulnerability has been used to distribute various malware, including Redline Stealer and SparkRAT.
Others include StealC, RedLine, Odebug and other Phemedrone variants, and NodeJS loaders and downloaders.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
In our case, the attacker entered the network over VPN (Username: Nexus, Password: Nexus123 - no MFA. Local admin.
The campaign also uses gaming-themed content and automated outreach to draw people toward its malware delivery ecosystem.
C:\Windows\System32\cmd.exe /c copy Yeast Yeast.cmd & Yeast.cmd
Suspicious use of WriteProcessMemory ... PID 2680 wrote to memory of 1712 ... PID 3316 wrote to memory of 3832
In our case, the attacker entered the network over VPN (Username: Nexus, Password: Nexus123 - no MFA. Local admin.
Related techniques include T1056 (Input Capture/keylogging) and T1557 (session/token interception), both observed across current stealer families.
stolen passwords, browser data, session cookies, and Active Directory credentials may support deeper access to corporate networks.
One component collected browser credentials, wallet-related information, and screenshots... stolen passwords, browser data, session cookies, and Active Directory credentials may support deeper access to corporate networks.
MITRE ATT&CK maps this behavior primarily to Credential Access (TA0006), specifically T1555 – Credentials from Password Stores and its sub-technique T1555.003 – Credentials from Web Browsers, covering theft of saved browser passwords, cookies, and autofill data.
Related techniques include T1056 (Input Capture/keylogging) and T1557 (session/token interception), both observed across current stealer families.
The proxy-list server at 212.193.30.45 supplied proxies.txt to infected machines, then redirected generic requests to GitHub... a separate host, 212.193.30.29, served the STANDOFF COORD operator console.
Un User-Agent WinHTTP malformé ... constitue une signature réseau distinctive.
345 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named stealer malware family mentioned as an example search term for marketplace monitoring; no operational details are provided in the content.
An information stealer used in the STANDOFF infection chain to capture sensitive user data; the report specifically notes browser credentials, passwords, browser data, session cookies, and potentially data supporting follow-on attacks.
Credential-stealing malware deployed in the bundle; the report notes MissionID @Tui and C2 185.215.113.44:23759.
An infostealer and early pioneer of the malware-as-a-service stealer model. The content describes it as a legacy but still relevant source of stolen credentials appearing in older logs used for follow-on cloud breaches.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.