Last seven days
- First activity
- Aug 10, 2026
- Last activity
- Aug 10, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
MetaStealer is an information-stealing malware family active since 2022 and commonly described as a derivative of RedLine with additional features and heavier obfuscation.
Profile source: Mallory opens in a new tabMetaStealer
MetaStealer is an information-stealing malware family active since 2022 and commonly described as a derivative of RedLine with additional features and heavier obfuscation. It has been observed primarily on Windows and macOS, with Windows variants implemented in .NET and macOS variants delivered as heavily obfuscated Go-based Mach-O binaries. The malware is designed to harvest sensitive data from compromised systems, including browser credentials, cookies, saved passwords, files, and in some cases cryptocurrency wallet data. Documented Windows capabilities also include keylogging, hidden VNC-style remote access, arbitrary command execution, system reconnaissance, persistence via scheduled tasks, and defense evasion through Microsoft Defender exclusions. Some reporting also links MetaStealer activity to techniques for bypassing Chromium Application-Bound Encryption to recover protected browser secrets.
On Windows, MetaStealer has been observed using encrypted configuration data and runtime string deobfuscation, communicating with command-and-control infrastructure over HTTP using JSON-based tasking. Reported tasking includes browser data theft from Chrome, Edge, and Firefox, command execution, and collection of host information. Persistence has been established through scheduled tasks, and some samples rename themselves and store bot identifiers locally. MetaStealer infrastructure has also been associated with domain generation algorithms, including a newer wordlist-based DGA, while gate servers appear to rely more on transport and protocol characteristics than on any specific domain.
On macOS, MetaStealer emerged during 2023 as a business-focused infostealer distributed through malicious application bundles packaged in DMG or ZIP archives. Social-engineering lures have included fake client project materials and software-themed installers. macOS variants have been observed stealing keychain data, saved passwords, files, and in some cases data associated with Telegram and Meta services. These samples were single-architecture Intel binaries and generally required users to bypass normal Apple trust protections to execute.
Observed delivery methods include malvertising, fake software installers, business-themed lure files, and social-engineering campaigns impersonating legitimate software or services. MetaStealer has been delivered in campaigns involving spoofed tax-related brands, fake AnyDesk installers, and malicious Google Ads impersonating products such as Mozilla Thunderbird and Microsoft Teams. It has also been referenced among infostealers implicated in broader credential-exposure ecosystems, including compromises where previously stolen credentials were later abused against cloud services. MetaStealer is best characterized as a cross-platform commodity infostealer with credential theft, browser data theft, exfiltration, persistence, and post-compromise tasking capabilities.
C2 tracking
Derp observations, rolling seven-day window
Samples
69a28d6d01d5497720485a24a3261cd340ddd6bbaaf15c40ad93f12f45ccda82 af42d5aa212f4d7be3dfe01013e846b0fd16b962a1ab871d178466258651b900 b6ab14a7bb5911d999522a21833acad0ecb5638c31d3d94b305f6b60fefb0c10 d2f3273710b161fc4edcc1e53bde7afbb33b3fc205b2fb46909dfdc15ed401e6 e461f2f91415fb621c849cf757fe6f8a1197f5fa4d4197590d335463fb1d4967 MITRE ATT&CK
Reporting
Connor Riley Moucka, a 26-year-old Canadian national, pleaded guilty in U.S. federal court for his role in a Snowflake-linked hacking and extortion campaign that compromised at least 165 organizations and exposed data tied to at least 100 million people. Prosecutors said the group used stolen credentials between February and October 2024 to access cloud-hosted customer environments, steal terabytes of sensitive data and billions of files, and extort victims by threatening to publish the information. Reported victims included AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, and LendingTree, with stolen records including banking data, Social Security numbers, passport numbers, driver’s license numbers, and DEA registration numbers. Investigators said the intrusions were not caused by a compromise of Snowflake itself but by previously exposed customer credentials, many traced to infostealer malware infections dating back to 2020. Mandiant found that at least 79.7% of the accounts used in the campaign had prior credential exposure, and observed the attackers using Snowflake’s SnowSight web interface, the SnowSQL CLI, DBeaver Ultimate, and a reconnaissance utility tracked as FROSTBITE to enumerate users, roles, IPs, session IDs, and organization names. Authorities said the conspiracy generated more than $2.5 million in ransom payments, while Moucka separately made about $495,000 selling stolen data on cybercrime forums; he was extradited to the United States and is scheduled to be sentenced on October 27, 2026.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.