Dutch police, the FBI, and international partners disrupted the RedLine and META infostealer operations in a coordinated action dubbed Operation Magnus, seizing or taking control of infrastructure used to run the malware-as-a-service platforms. Authorities said they hacked or dismantled servers tied to both strains, replacing criminal infrastructure with law-enforcement notices and aiming to cut off panels and backend systems used by cybercriminal customers to steal credentials, browser data, cookies, and cryptocurrency wallet information from victims worldwide.
The U.S. Department of Justice said the United States joined the international action and separately unsealed charges against a Russian national accused of helping develop and administer RedLine. Reporting on the operation said investigators targeted what officials described as the core infrastructure behind two of the most widely used infostealers in the cybercrime ecosystem, combining technical disruption with criminal charges to weaken both the malware services and the people allegedly operating them.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
U.S. authorities unsealed charges against Russian national Maxim Rudometov, alleging he developed and administered the RedLine infostealer. The case linked the criminal charges to the broader international disruption effort against RedLine and META.
Dutch police, working with the FBI and other partners, hacked, seized, or otherwise disrupted servers tied to RedLine and META, with officials describing the action as affecting all known servers for the malware operations. The takedown was intended to interrupt the infostealers' command-and-control and criminal business activity.
Authorities from the Netherlands, the United States, and international partners carried out Operation Magnus to disrupt the RedLine and META infostealer ecosystem. The operation targeted the malware families' infrastructure and supporting criminal services.
Before the law enforcement action, RedLine and META were operating as prominent infostealer malware services used to steal credentials, financial data, and other sensitive information from victims worldwide. Their infrastructure and customer base made them significant cybercrime enablers.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
7 references tracked. Mallory keeps watching after this page renders.
cyberscoop.com
Open sourcescworld.com
Open sourcehelpnetsecurity.com
Open sourcejustice.gov
Open sourcecyberscoop.com
Open sourcehelpnetsecurity.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.