META Stealer is a Windows information stealer marketed as an improved derivative or clone of RedLine and offered to cybercriminals under a malware-as-a-service model. It harvests credentials stored in Chromium- and Firefox-based browsers, browser cookies, and cryptocurrency-wallet data; reported variants have also bypassed Chromium App-Bound Encryption protections. META has been distributed in malspam campaigns using fraudulent fund-transfer and DocuSign-themed macro-enabled spreadsheet attachments. Enabling macros launches an obfuscated staged payload chain that assembles and executes the stealer. META establishes Windows Registry-based persistence, communicates with command-and-control infrastructure after reboot, and uses PowerShell to add Microsoft Defender exclusions for executable files. META was sold through criminal marketplaces and was disrupted alongside RedLine in the multinational Operation Magnus action in October 2024. The name "Meta" has also been used for an unrelated Go-based Linux SSH-propagation tool; that malware is distinct from META Stealer.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
One thing to note is that META modifies Windows Defender via PowerShell to exclude .exe files from scanning, to protect its files from detection.
If the scanning and authentication are successful, command execution occurs to install “mysql,” an XMRig CoinMiner, on the Attack Target server.
If the scanning and authentication are successful, command execution occurs to install “mysql,” an XMRig CoinMiner, on the Attack Target server.
The analysis draws on approximately 44 million infostealer logs and recommends monitoring for "credential exposure," "credential theft," and compromised data following law-enforcement takedowns.
“When executed, RedLine would steal data, including access devices, from victims’ computers.” Infostealers thieve billions of user credentials such as passwords annually.
Scanning and login attempts targeting SSH service honeypots occurred from multiple attack sources.
provided criminals access to “bots” or “browser fingerprints” ... including IP addresses, session cookies, operating system information, and plugins
A clear and persistent sign of the infection is the EXE file generating traffic to a command and control server at 193.106.191[.]162, even after the system reboots, restarting the infection process on the compromised machine.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer named as a target of Operation Magnus. The content provides no further technical or operational detail.
Named as infostealer infrastructure dismantled during Operation Magnus in October 2024; mentioned as background in a broader discussion of infostealers.
Go-based propagation malware that scans SSH services using supplied ranges and credentials, executes commands on successful login, installs XMRig, and reports results via HTTP POST.
A RedLine clone mentioned as part of the broader infostealer ecosystem and takedown context.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.