RedLine Stealer is a Windows information-stealing malware family first observed in 2020 and commonly distributed through malicious or unofficial downloads, including cracked software and applications masquerading as legitimate tools. It harvests browser-resident credentials, cookies, autofill data, payment-card information, and active session artifacts from Chromium- and Gecko-based browsers. Stolen session cookies can be replayed to hijack authenticated web accounts, potentially bypassing login-time multifactor authentication.
RedLine collects host profiling data, including operating-system, hardware, installed-software, security-product, process, language, and public-network information. It can search for and exfiltrate documents and other files, capture desktop screenshots, and target credentials or session data belonging to cryptocurrency wallets, Discord, FileZilla, Steam, Telegram, and VPN applications. Its cryptocurrency-wallet targeting includes browser-extension and desktop wallet data.
RedLine communicates with command-and-control infrastructure to exfiltrate collected data and can accept remote tasking to download and execute additional payloads, run shell commands, and open web resources. Samples have used encrypted embedded payloads, hidden execution, and environment-aware behavior. RedLine has been associated with theft of authenticated Claude browser sessions from compromised Windows endpoints, allowing attackers to consume victims’ account usage. It is a commodity infostealer and should not be treated as intrinsically attributable to a specific threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Microsoft created a security patch for Windows systems to fix the vulnerability, giving it the CVE identifier CVE-2024-43451. The security patch was published on November 12th, 2024. | The other files detected exploiting the new vulnerability followed a similar attack scenario that ended with the installation of Redline Stealer malware.
The embedded file with a randomized file name exploits a particular vulnerability —CVE-2017-11882—to execute malicious code to deliver and execute malware on a victim’s device. | Redline (also known as Redline Stealer) is a commercial malware family designed to collect sensitive information from infected devices, such as saved credentials, autocomplete data, credit card information, and more.
17 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Starting in mid-March 2022, eSentire observed an increase in the deployment of Redline Stealer malware. Redline Stealer is an information stealing malware that was first identified in early 2020.
2020 (or earlier): The Infection The campaign operator gets infected by RedLine Stealer. Admin credentials are exfiltrated to the Dark Web.
2020 (or earlier): The Infection The campaign operator gets infected by RedLine Stealer. Admin credentials are exfiltrated to the Dark Web.
In many cases, ZingoStealer also delivers additional malware such as RedLine Stealer and the XMRig cryptocurrency mining malware to victims.
Batloader has been observed to drop several malware payloads, such as Ursnif, Vidar, Bumbleloader, RedLine Stealer, ZLoader, Cobalt Strike, and SmokeLoader.
When KELA first observed the threat actor “_META_” offering a new stealer, it was marketed as having the same functionality and panel as RedLine Stealer.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The extracted resource is decrypted using the AES algorithm, with the key and IV being hard-coded in the executable.
The stealer implements the following actions that extend its functionality: Download, RunPE, DownloadAndEx, OpenLink, and Cmd.
A bad actor was “using those login sessions to access Claude accounts and consume their usage.”
« Ces programmes copient les cookies de connexion stockés dans le navigateur » ; « Un attaquant qui copie ce cookie et le rejoue depuis un autre appareil apparaît alors [...] comme la personne ayant déjà réussi cette vérification ».
OpenSubKey is utilized to open the “SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall” registry key, which contains the installed programs.
The ScanResult.MachineName value is set to the username extracted from the Environment.UserName property.
1,530 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Voleur d’informations utilisé pour copier les cookies de session stockés dans les navigateurs ainsi que les mots de passe enregistrés, permettant le détournement de sessions et le contournement de l’authentification à deux facteurs.
Named as one of several infostealers identified on impacted systems that can collect login cookies, application credentials, and browser passwords, enabling theft of active Claude sessions.
An information stealer identified as capable of stealing active Claude session cookies from infected Windows computers, enabling account access without passwords and bypassing MFA and SSO.
Infostealer used to steal Claude login sessions from affected Windows computers, enabling unauthorized account access and consumption of available tokens.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.