META is an information-stealing malware family closely associated with RedLine and widely described as a derivative or clone of it. It emerged as a commercially offered stealer in the cybercrime ecosystem and was marketed as an improved RedLine alternative. META became prominent in 2024 as one of the most prevalent infostealers in circulation, and together with RedLine was linked to a large share of global infostealer infections before both operations were disrupted by international law enforcement during Operation Magnus in October 2024.
META is designed to harvest sensitive user data from compromised systems, including browser-stored credentials, cookies, autofill data, and cryptocurrency wallet information. Reporting also indicates it has been among the malware families capable of bypassing Chrome App-Bound Encryption protections. Its core targeting has centered on Windows endpoints in malspam-delivered stealer campaigns, where it has been observed using macro-enabled document lures, staged payload retrieval, obfuscation, persistence via the Windows Registry, and PowerShell-based weakening of Microsoft Defender protections.
A distinct Linux variant or component using the same name has also been reported in SSH-focused intrusion campaigns against poorly managed Linux servers. In that activity, META was implemented in Go as propagation malware that scanned for SSH services, attempted authentication using supplied credential material, and executed commands to deploy an XMRig-based coin miner on newly compromised hosts. In that role, META functioned as a spreader and installer rather than a browser-data stealer.
META has been distributed through malicious spam and has also been referenced in broader discussions of infostealer delivery via cracked software, fake installers, and other socially engineered infection chains. Its operational history, market presence, and overlap with RedLine infrastructure made it a significant part of the modern infostealer economy until the 2024 takedown, although repackaged or residual variants may continue to appear.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
One thing to note is that META modifies Windows Defender via PowerShell to exclude .exe files from scanning, to protect its files from detection.
If the scanning and authentication are successful, command execution occurs to install “mysql,” an XMRig CoinMiner, on the Attack Target server.
If the scanning and authentication are successful, command execution occurs to install “mysql,” an XMRig CoinMiner, on the Attack Target server.
“When executed, RedLine would steal data, including access devices, from victims’ computers.” Infostealers thieve billions of user credentials such as passwords annually.
Scanning and login attempts targeting SSH service honeypots occurred from multiple attack sources.
provided criminals access to “bots” or “browser fingerprints” ... including IP addresses, session cookies, operating system information, and plugins
A clear and persistent sign of the infection is the EXE file generating traffic to a command and control server at 193.106.191[.]162, even after the system reboots, restarting the infection process on the compromised machine.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as infostealer infrastructure dismantled during Operation Magnus in October 2024; mentioned as background in a broader discussion of infostealers.
Go-based propagation malware that scans SSH services using supplied ranges and credentials, executes commands on successful login, installs XMRig, and reports results via HTTP POST.
A RedLine clone mentioned as part of the broader infostealer ecosystem and takedown context.
An infostealer malware family derived from RedLine, mentioned as a target of Operation Magnus.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.