Researchers reported continued RedLine Stealer activity across multiple delivery chains, including phishing sites, fake cryptocurrency tools, trojanized installers, malicious Office documents, and botnet-driven payload drops. Recent analysis showed a sample disguised as a fake Netflix checker decrypting an embedded payload, writing %AppData%\winlogon.exe, and contacting siyatermi.duckdns[.]org:17044 over SOAP/HTTP via Windows Communication Foundation. Separate investigations tied RedLine delivery to AutoIt-based wrappers used on phishing pages impersonating a cryptocurrency exchange, YouTube lures for a fake Binance autobuy bot hosted on GitHub, and Excel exploit chains abusing CVE-2017-11882 to fetch and inject the stealer.

Pull IOCs and campaign context straight into your stack.
16 events from the most recent confirmed update back to the earliest known activity.
Kroll reported a surge in Q4 2023 cases involving users downloading PdfConverters.exe from the malicious site pdfconvertercompare[.]com. Kroll identified the file as RedLine Stealer and noted it had low antivirus detection at the time.
EclecticIQ observed RedLine sample volume increasing again in the second week of August 2023. Later samples also added a botnet authorization module not seen in versions from before August, indicating increased automation.
EclecticIQ reported that a small initial cluster of RedLine activity peaked around mid-July 2023. This wave then tapered significantly by early August 2023.
EclecticIQ reported passive DNS records indicating the 2023 RedLine campaign likely began on April 17, 2023, when several malicious domains were associated with the Finnish IP 77.91.68.141. Those domains were later detected in RedLine variants and assessed as part of the campaign infrastructure.
EclecticIQ observed 2023 RedLine campaign variants appearing in VirusTotal starting in the last week of April 2023. The firm assessed this period likely reflected initial testing of redeveloped samples after a relative lull in 2022.
K7 Labs analyzed a resurfacing RedLine Stealer sample delivered as an NSIS-compiled binary that dropped executables into AppData\Roaming and used a packed loader to hollow a suspended AppLaunch.exe process. The sample used geolocation checks, decoded C2 185.200.191[.]18:80 via a Base64-XOR-Base64 routine, and included browser, Telegram, Discord, FileZilla, VPN theft plus encoded cryptocurrency wallet addresses consistent with clip-and-switch theft.
In the Binance-themed campaign, Netskope assessed the first-stage RedLine loader was likely compiled on April 5, 2022. The loader later decrypted additional stages and injected the final payload into processes such as RegSvcs.exe or AppLaunch.exe.
Netskope identified an April 2022 RedLine Stealer campaign in which YouTube videos promoted a fake Binance Mystery Box autobuy bot hosted on GitHub. The archive delivered a packed RedLine loader and related files designed to appear legitimate.
ASEC identified a RedLine Stealer campaign that used YouTube videos advertising Valorant cheats to lure victims to an anonfiles-hosted RAR archive containing a fake "Cheat installer.exe." Once run, the malware stole browser, wallet, VPN, FileZilla, Minecraft, Steam, and Discord data and exfiltrated it to a Discord server via a webhook POST request.
SANS ISC analyzed a malicious Python script that downloaded an encrypted payload from an FTP server, decrypted it with a hardcoded key, and injected RedLine Stealer into memory using shellcode and a runpe-style loader. The sample attempted to contact command-and-control server 78.24.222.162 on port 37819, which was offline at the time of analysis.
Qualys identified a RedLine InfoStealer campaign active from late January through March 2022 that used fake cracked software archives hosted on Discord’s CDN, URL shorteners, and fake websites to lure victims. The infection chain used simple .NET loaders and PureCrypter to inject RedLine, with some loaders signed using a hijacked Exodus Movement Inc. certificate and payloads ultimately connecting to 193.203.203.82:23108.
ZeroFox researchers first spotted the Golang-based Kraken botnet in October 2021 and observed it using SmokeLoader to infect Windows systems. Monitoring from October through December 2021 showed the operator focused on deploying RedLine Stealer as a follow-on payload.
Trend Micro documented a campaign using fake installers and cracked software lures, including TeamViewer and VueScan Pro, to infect users with multiple malware families. The bundled payloads included Trojan.Win64.REDLINESTEALER.N alongside credential theft, persistence, and downloader components.
SecurityScorecard analyzed a RedLine Stealer sample disguised as a fake Netflix checker that decrypted an embedded payload to %AppData%\winlogon.exe and communicated with siyatermi.duckdns[.]org:17044 over SOAP/HTTP. The report detailed theft of browser, wallet, Discord, FileZilla, Steam, Telegram, VPN, file, screenshot, and host reconnaissance data.
Zscaler analyzed an ongoing AutoIt-based malware campaign that used phishing sites and self-extracting archives to deliver either RedLine Stealer or a new CyberGate RAT variant. The report linked the activity to phishing pages impersonating the Resistance cryptocurrency exchange and identified delivery infrastructure including resisproject[.]me, resisproject[.]cc, and a RedLine C2 at yellowbag[.]top.
FortiGuard Labs analyzed a malicious Excel document chain exploiting CVE-2017-11882 to download RedLine from lutanedukasi[.]co[.]id. The loader decrypted an embedded payload, used process hollowing, and established persistence with a scheduled task named Nafdfnasia.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 103 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
13 references tracked. Mallory keeps watching after this page renders.
securityscorecard.com
Open sourcezscaler.com
Open sourcekroll.com
Open sourceblog.eclecticiq.com
Open sourceisc.sans.edu
Open sourcetrendmicro.com
Open sourcequalys.com
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.