U.S. authorities extradited Armenian national Hambardzum Minasyan to face charges for allegedly helping develop and operate the RedLine infostealer malware, a tool widely used to steal login credentials and other sensitive data from victims’ computers. Prosecutors accused Minasyan of maintaining key RedLine infrastructure, including virtual private servers, internet domains, malware distribution repositories, and a cryptocurrency account used to collect payments from affiliates who deployed the malware.
The indictment charges Minasyan with conspiracy to commit access device fraud, conspiracy to violate the Computer Fraud and Abuse Act, and conspiracy to commit money laundering. The case follows the multinational Operation Magnus disruption of the RedLine and Meta infostealers in 2024, carried out with authorities in the United States, Belgium, the Netherlands, and Eurojust. U.S. officials had previously charged alleged co-conspirator Maxim Rudometov, identified as a RedLine developer and administrator, and also launched a public website for victims seeking information and assistance.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
After his extradition, prosecutors charged Minasyan with conspiracy to commit access device fraud, conspiracy to violate the Computer Fraud and Abuse Act, and conspiracy to commit money laundering. The Justice Department alleges he helped maintain RedLine servers, domains, and malware distribution repositories.
U.S. authorities announced that Hambardzum Minasyan was extradited from Armenia to the United States over his alleged role in operating RedLine. Prosecutors say he helped host infrastructure, distribute the malware to affiliates, and receive affiliate payments via cryptocurrency.
During the 2024 international operation, U.S. authorities unsealed charges against Russian national Maxim Rudometov for his alleged role in developing and administering the RedLine infostealer.
In October 2024, U.S., Belgian, Dutch, and Eurojust authorities carried out Operation Magnus to disrupt the RedLine and Meta infostealer infrastructure. The operation also included the launch of a public victim-resource website.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcetherecord.media
Open sourcecyberscoop.com
Open sourcejustice.gov
Open sourcespycloud.com
Open sourceinfosec.pub
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.