RedLine Stealer is a Windows information-stealing malware family written in C# that emerged in early 2020 and became one of the most prevalent commodity stealers in the cybercrime ecosystem. It is commonly sold and distributed through malware-as-a-service and affiliate-driven channels, and has been widely observed in stealer-log marketplaces, pay-per-install operations, and bundled crimeware delivery chains.
RedLine primarily targets browser-stored data and other user secrets. Documented capabilities include theft of saved credentials, cookies, autofill data, authentication tokens, cryptocurrency wallet data, and related host information. Stolen session material can enable downstream account takeover and MFA bypass when valid cookies or tokens are captured. RedLine infections are typically broad and opportunistic rather than tightly pre-targeted, with operators or downstream buyers selecting valuable victims after collection.
The malware is frequently delivered by other loaders and traffic-distribution operations, including drive-by download chains, trojanized software ecosystems, malvertising, and phishing or spearphishing campaigns. It has been observed as a payload delivered by families and services such as Dolphin Loader, Amadey, and StealC-linked operations, and it also appears in broader criminal ecosystems alongside stealers, RATs, miners, and loaders. RedLine infrastructure has additionally been linked to targeted fraud and business-email-compromise-style activity in the maritime supply chain, where attacker infrastructure associated with RedLine overlapped with spearphishing operations delivering other malware.
On infected systems, RedLine performs host and process discovery and communicates with command-and-control infrastructure using characteristic SOAP-based HTTP traffic seen in multiple investigations. Sandbox reporting also shows process discovery, registry queries, storage-device enumeration, dropped components, and suspicious memory-writing or injection-related behavior in some samples. The family has remained operational through repackaged and legacy variants even after major law-enforcement disruption of backend infrastructure in 2024 and subsequent takedown activity in 2025.
RedLine has been one of the dominant infostealer families affecting enterprises and consumers alike, with particular impact on developer, cloud, cryptocurrency, and SaaS-linked accounts because a single compromised Windows endpoint can expose credentials and active sessions spanning personal and corporate environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ClearSky Cyber Security has uncovered a new zero-day vulnerability, CVE-2024-43451, actively exploited in the wild, targeting Windows systems primarily in Ukraine. This flaw enables attackers to exploit URL files for malicious activity by performing actions as simple as a single right-click.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The RedLine Stealer Trojan is used to spread a malware called Bobik.
LAPSUS$ acquired and used the Redline password stealer in their operations.
Amadey is a modular Windows botnet sold as MaaS by author "InCrease" on XSS/Exploit forums, active since 2018. It commonly drops Lumma, StealC, RedLine, CoinMiners, and RATs.
ClearSky researchers observed that this vulnerability has been used to distribute various malware, including Redline Stealer and SparkRAT.
Others include StealC, RedLine, Odebug and other Phemedrone variants, and NodeJS loaders and downloaders.
Hudson Rock researchers investigated the alleged breaches and found the threat actor relied on distributing infostealers such as RedLine, Lumma, or Vidar... to harvest credentials.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Compromised accounts could be used to facilitate fraud, account takeover, or secondary market ticket resale schemes.
Operators distribute malware through pirated software repositories, malvertising networks, and compromised websites with the goal of infecting as many machines as possible.
Instead, it became the starting point for tracing a coordinated spear phishing and business email compromise campaign.
When successfully deployed and executed, information-stealing malware can harvest credentials (usernames, passwords, and session cookies) from infected environments and export them as logs to the attackers’ server.
Security researchers documented widespread fraud campaigns involving fake ticketing platforms, fraudulent domains impersonating official World Cup services, credential harvesting operations, counterfeit mobile applications, and account compromise activity.
Keylogging ( T1056.001, Credential Access / Collection ) - перехват нажатий клавиш для захвата вводимых вручную паролей, включая те, что не сохраняются в браузере.
They extract: Browser-saved credentials, autofill data Active session cookies (which bypass MFA entirely) Authentication tokens for GitHub, GitLab, AWS, Azure, and GCP
These programs extract saved credentials, session cookies, authentication tokens, and configuration files from infected endpoints, then exfiltrate the data to attacker-controlled infrastructure.
Если атакующий получил активную сессию Windows (через RDP, физический доступ, малварь), DPAPI-защита Chrome снимается вызовом CryptUnprotectData без дополнительных секретов. Это прямой вектор для техники Credentials from Web Browsers (T1555.003, Credential Access) - одна из самых популярных техник в арсенале стилеров (RedLine, Raccoon, Vidar).
Checks computer location settings ... Looks up country code configured in the registry, likely geofence. Query Registry T1012
Banking trojans and information stealers materialized as the second most prevalent type of cybercrime, with malware families like RedLine, Lumma, LokiBot, Negasteal, and ZBot taking up the top spots.
Security researchers documented widespread fraud campaigns involving fake ticketing platforms, fraudulent domains impersonating official World Cup services, credential harvesting operations, counterfeit mobile applications, and account compromise activity.
VMRay Labs continued the research with “212.193.30[.]45”, which behaves not as a console but as a proxy/redirector that fronts the actor’s infrastructure behind the GitHub domain.
The SOAPAction header pointing at tempuri.org is consistent with RedLine’s SOAP-based communication which confirms the family.
310 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential and information stealer delivered as part of the broader operation’s commodity malware payload set.
An infostealer malware family used to steal credentials and produce stealer logs. In this content it is identified as one of the three malware families responsible for most observed credential exposure across AI and developer platforms.
Information-stealing malware active since around 2020 that commonly spreads via cracked software, malicious ads, and phishing attachments, and steals passwords, browser cookies, and cryptocurrency wallet data. In this case, its leaked C2 infrastructure helped uncover a broader phishing and BEC-style operation targeting the maritime supply chain.
Commodity infostealer first observed in early 2020 and sold as Malware-as-a-Service. It harvests credentials, browser cookies, autofill data, and cryptocurrency wallets, then bundles the stolen data into logs for sale.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.