Threat researchers reported multiple COVID-19-themed phishing campaigns distributing the RedLine Stealer malware by disguising payloads as legitimate pandemic-related software and information. In one campaign, attackers used an Omicron Stats.exe lure tied to the Omicron outbreak; in another, they impersonated a coronavirus research effort and pushed a fake Folding@home application named foldingathomeapp.exe. Researchers assessed email as the likely delivery vector, with the campaigns exploiting public anxiety and curiosity around the pandemic to drive downloads.
Once executed, RedLine harvested browser credentials, cookies, credit card and autocomplete data, cryptocurrency wallet artifacts, Telegram and Discord data, and detailed host information. Fortinet said the Omicron-themed sample copied itself into the victim’s roaming AppData directory, established persistence through a scheduled task, and communicated with a command-and-control server at 207.32.217.89:14588 using a distinctive authorization header; Proofpoint and BleepingComputer also noted RedLine receives remote tasking after infection. Victims were observed across at least 12 countries, indicating broad opportunistic targeting rather than a narrowly focused operation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
FortiGuard Labs observed repeated communication between the campaign's C2 server at 207.32.217.89 and Telegram network IP 149.154.167.91, suggesting possible use of abused Telegram infrastructure. The observed activity spanned from November 26 to December 23, 2021.
Proofpoint discovered a phishing campaign that used coronavirus cure messaging and a fake Folding@home download to distribute the RedLine information-stealing Trojan. The emails urged recipients to install a file named "foldingathomeapp.exe," which was actually malware.
FortiGuard Labs discovered a Windows RedLine Stealer variant masquerading as "Omicron Stats.exe" and assessed it as a COVID-themed social-engineering campaign likely delivered by email. Researchers said the malware stole credentials, browser and wallet data, Telegram and Discord artifacts, and host information, while targeting victims across 12 countries.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 38 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
3 references tracked. Mallory keeps watching after this page renders.
fortinet.com
Open sourcebleepingcomputer.com
Open sourceproofpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.