Researchers detailed a MetaStealer infection chain delivered through malicious email attachments and links, including Excel macro documents and OneNote files, that infected Windows systems and established persistence for follow-on payload delivery. In the observed campaigns, enabling macros or opening the lure file launched scripts that retrieved components from GitHub and transfer.sh, built a persistent executable on the host, and modified HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell so the malware would restart after reboot. Analysts said the infrastructure remained active near the time of publication, and network traffic to 193.106.191.162:1775 matched EmergingThreats Pro detections for Win32/MetaStealer activity.
Separate reverse engineering showed MetaStealer used XOR-based string decryption and a domain generation algorithm (DGA) to supplement or replace static command-and-control infrastructure by generating multiple .xyz domains for beaconing. Decrypted strings and observed behavior indicated capabilities beyond credential theft, including SOCKS proxying, backconnect access, firewall rule manipulation, shellcode execution, and tasking endpoints, underscoring that MetaStealer functioned as a flexible post-compromise stealer and access tool rather than a simple infostealer.

Pull IOCs and campaign context straight into your stack.
10 events from the most recent confirmed update back to the earliest known activity.
On May 11, 2023, OpenAnalysis published analysis of a MetaStealer sample, including YARA rules, XOR-decoded strings, and evidence of browser-data theft, tasking paths such as /api/client/new and /tasks/collect, and probable C2 port 1775. The analysis also documented a PowerShell command to add a Microsoft Defender exclusion for .exe files, indicating defense-evasion behavior.
EmergingThreats Pro signatures 2851362 and 2851363 for Win32/MetaStealer Related Activity were released on April 1, 2022. These signatures detected the malware's GET and POST traffic to its command-and-control infrastructure.
At least 16 samples of a malicious Excel attachment tied to a MetaStealer campaign had been submitted to VirusTotal starting on March 30, 2022. The files were distributed as email attachments and required victims to enable macros.
Proofpoint reported that RedLine Stealer was under active development and that new features such as cold cryptocurrency wallet theft were added in March 2020. This marked an expansion of the malware's theft capabilities.
In March 2020, Proofpoint researchers discovered a phishing campaign distributing RedLine Stealer, primarily targeting U.S. healthcare and manufacturing organizations. The emails used COVID-19 and Folding@home-themed lures and directed victims to a BitBucket-hosted payload.
Advertisements for RedLine Stealer appeared on criminal forums as early as February 20, 2020, offering the malware for sale in multiple pricing tiers. Some ads also offered cracked versions.
At the time of writing, Walmart reported that the generated domain wgcuwcgociewewoo.xyz resolved and that another hostname, mmswgeewswyyywqk.xyz, had previously been active. Both domains were in the DGA-derived list for seed 0x1234.
Walmart researchers analyzed a MetaStealer sample and documented its XOR-based string decryption and domain generation algorithm. They found the malware generated multiple .xyz domains and appeared to use DGA-derived infrastructure as a primary C2 method.
KELA had previously observed the threat actor '_META_' marketing a new stealer described as having the same functionality and panel as RedLine Stealer. This linked MetaStealer's ecosystem to RedLine-like capabilities.
Before the Walmart analysis, Unit 42 had tweeted about a campaign in which a malicious email link downloaded a OneNote file that dropped and executed MetaStealer. This documented a separate delivery method for the malware.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 34 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
research.nccgroup.com
Open sourceisc.sans.edu
Open sourceisc.sans.edu
Open sourceresearch.openanalysis.net
Open sourcemedium.com
Open sourceproofpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.