MetaStealer is an information-stealing malware family that emerged in 2022 and has been widely described as a derivative or variation of RedLine Stealer. It is primarily associated with Windows infections, where it has been observed as a commodity infostealer with broader remote-access and post-compromise functionality than simple credential theft alone. Separate reporting has also identified a distinct macOS infostealer family using the same name, targeting business users through malicious application bundles and social-engineering lures. Across both ecosystems, MetaStealer is used to harvest sensitive data from compromised hosts and exfiltrate it to attacker-controlled infrastructure.
On Windows, MetaStealer has been delivered through multiple initial-access vectors, including malspam with malicious Excel attachments requiring macro execution, phishing campaigns using OneNote payloads, fake software installers, and malvertising that impersonates legitimate software brands. Observed infection chains have used scripts and staged payload retrieval from public hosting services before establishing persistence and contacting command-and-control infrastructure. Persistence mechanisms reported for Windows variants include scheduled tasks and user logon shell modification. Defense-evasion behavior includes runtime string obfuscation and attempts to weaken Microsoft Defender protections by adding exclusions.
Windows MetaStealer is designed to steal browser data from Chromium-based browsers and Firefox, including cookies and saved passwords, and reporting also attributes theft of files and, in some cases, cryptocurrency-wallet-related data. Technical analyses have recovered references to browser storage artifacts and collection workflows consistent with credential and session theft. Some variants also support keylogging, arbitrary command execution, and hidden remote-control functionality, indicating use beyond pure smash-and-grab theft. Additional analyses describe command-and-control tasking, shellcode-related functionality, SOCKS or backconnect capability, and other post-exploitation features. MetaStealer has also been observed adapting to newer browser protections, including techniques associated with Chromium Application-Bound Encryption bypass via COM-based interaction with browser elevation services.
MetaStealer communications have been linked to structured HTTP-based tasking and collection endpoints, and multiple reports describe the family’s use of domain generation algorithms for command-and-control discovery. Researchers have documented both older pseudo-random domain generation and newer wordlist-based DGA behavior, with gate infrastructure appearing relatively domain-agnostic and relying on consistent ports, URIs, and headers. Obfuscation is a recurring trait in Windows samples, including XOR-based string decoding and encrypted configuration data.
The malware has been associated with criminal distribution as well as use in targeted phishing operations. Reporting has linked MetaStealer to campaigns run by Sticky Werewolf against Russian scientific, industrial, and government-related organizations, alongside other malware used by that actor. MetaStealer has also been cited among infostealer families whose stolen credentials were later abused in follow-on intrusions, including compromises of Snowflake customer environments.
A macOS malware family also tracked as MetaStealer appeared in 2023. That family is a Go-based infostealer distributed in malicious DMG and ZIP lures, often themed around business communications or fake clients. It targets Intel-based macOS systems and has been observed stealing keychain data, saved passwords, and files, with some variants also referencing Telegram and Meta-related data. Its delivery model differs from many macOS stealers by focusing on business-themed social engineering rather than primarily cracked-software lures.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Unit42 recently tweeted about a campaign starting with a malicious email link that downloads a OneNote file used to drop and execute MetaStealer.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
В ĸачестве первоначального веĸтора атаĸ группа использует фишинговые рассылĸи по элеĸтронной почте с вредоносными вложениями... Злоумышленники отправляли вредоносные письма... В качестве приманки Sticky Werewolf использовали поддельное письмо от Минпромторга.
Decrypted Strings: ... Failed to create task definition action = allow program = "
"powershell -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionExtension \"exe\""
...both being Go-based infostealers that also use osascript to display error messages to the user on execution...
File name: open.vbs ... After enabling macro, this VBS file is used to create the persistent EXE | After enabling macro, this VBS file is used to create the persistent EXE
This means that to gain execution, the threat actor would likely need to guide or persuade the victim to override protections such as Gatekeeper and OCSP.
After landing on the C2 routine, instead of decrypting a static list of servers, the sample used a domain generation algorithm[3], (DGA) to derive the list.
After seeing references to backconnect, socks, and loader id’s in the decrypted strings, we can see that the improvements made to this tool now offer more than just credential theft.
127 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
MetaStealer is described as using a new wordlist-based DGA while older DGA infrastructure remains active. Its gate/proxy servers are domain-agnostic and rely more on IP, port, URI, and HTTP headers for traffic forwarding.
MetaStealer is described as malware using both an older and a new wordlist-based DGA for C2-related domain generation, with gate/proxy servers that are largely agnostic to the domain used and instead rely on IP, port, URI, and HTTP headers.
Referenced only as a comparison family that did not technically match the observed sample.
Инфостилер, упомянутый как один из источников украденных credential-пар, использованных в кампании против Snowflake.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.