MetaStealer is a name used for distinct Windows and macOS information-stealing malware families. The Windows family emerged in 2022 and was advertised as a derivative of RedLine Stealer with additional features. It harvests credentials, browser cookies, and files from compromised systems. Its relationship to RedLine can cause signature-based detection to classify some samples as RedLine.
Windows MetaStealer is primarily implemented in .NET. Observed variants employ control-flow and proxy-call obfuscation, encrypted configuration strings, XOR-based string encoding, and junk code to impede analysis. Command-and-control implementations include domain generation algorithms, with both an older algorithm and a newer wordlist-based algorithm observed. Infection chains have established persistence through Windows logon configuration, retrieved additional executable components, and attempted to weaken Microsoft Defender protection by excluding executable files from scanning.
Windows distribution methods include malicious email attachments containing macro-enabled Excel documents, email links delivering weaponized OneNote documents, and Google Ads impersonating legitimate applications. Campaigns have also used Roblox impersonation and tax-related lures. An updated browser-theft implementation observed in September 2024 bypasses Chrome Application-Bound Encryption by impersonating a SYSTEM token and invoking the Chrome elevation service through COM to decrypt the protected browser key. This implementation requires elevated privileges and enables theft of protected authentication cookies. MetaStealer has been associated with Sticky Werewolf operations. Credentials exposed by MetaStealer were also among those used in UNC5537 compromises of Snowflake customer environments; this does not establish that UNC5537 deployed the malware itself.
The separately identified macOS family was observed in 2023 and targets business users through malicious application bundles packaged in disk images and ZIP archives. Social-engineering lures include purported client briefs, design projects, and legitimate software installers. Its heavily obfuscated Go executables target Intel x86-64 Macs and require Rosetta to execute on Apple silicon. It extracts saved passwords and keychain data and steals files. Observed samples were unsigned, and some variants remained undetected after Apple introduced partial XProtect coverage. The macOS family should not be treated as a macOS port of the Windows RedLine-derived family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Unit42 recently tweeted about a campaign starting with a malicious email link that downloads a OneNote file used to drop and execute MetaStealer.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
В ĸачестве первоначального веĸтора атаĸ группа использует фишинговые рассылĸи по элеĸтронной почте с вредоносными вложениями... Злоумышленники отправляли вредоносные письма... В качестве приманки Sticky Werewolf использовали поддельное письмо от Минпромторга.
Decrypted Strings: ... Failed to create task definition action = allow program = "
"powershell -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionExtension \"exe\""
File name: open.vbs ... After enabling macro, this VBS file is used to create the persistent EXE | After enabling macro, this VBS file is used to create the persistent EXE
These malicious Excel files are distributed as email attachments. | Traffic generated after enabling Excel macro
Decrypted Strings: ... Failed to create task definition action = allow program = "
REDLINE uses a string obfuscation technique... METASTEALER ... employ[s] obfuscation methods, including obscuring the control flow... STEALC encrypts its strings using a combination of Base64 + RC4.
REDLINE [uses] malicious websites hosting seemingly legitimate applications... METASTEALER [was] encountered ... within a campaign masquerading as Roblox.
METASTEALER requires elevated access because it attempts to impersonate the SYSTEM token during execution; it uses a ContextSwitcher class for token impersonation before decrypting the Chrome key.
Infostealers implement bypasses around Chrome Application-Bound Encryption to retrieve cookie data; STEALC, METASTEALER, PHEMEDRONE, XENOSTEALER, and LUMMA recover cookies in plaintext.
After landing on the C2 routine, instead of decrypting a static list of servers, the sample used a domain generation algorithm[3], (DGA) to derive the list.
After seeing references to backconnect, socks, and loader id’s in the decrypted strings, we can see that the improvements made to this tool now offer more than just credential theft.
128 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named stealer accounting for 995 of the 1,544 malware domains reported under .xyz. Its capabilities and delivery methods are not described.
MetaStealer is described as using a new wordlist-based DGA while older DGA infrastructure remains active. Its gate/proxy servers are domain-agnostic and rely more on IP, port, URI, and HTTP headers for traffic forwarding.
MetaStealer is described as malware using both an older and a new wordlist-based DGA for C2-related domain generation, with gate/proxy servers that are largely agnostic to the domain used and instead rely on IP, port, URI, and HTTP headers.
Referenced only as a comparison family that did not technically match the observed sample.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.