Skip to content

MetaStealer

MetaStealer is an information-stealing malware family that emerged in 2022 and has been widely described as a derivative or variation of RedLine Stealer.

Profile source: Mallory opens in a new tab

MetaStealer

Family profile

MetaStealer is an information-stealing malware family that emerged in 2022 and has been widely described as a derivative or variation of RedLine Stealer. It is primarily associated with Windows infections, where it has been observed as a commodity infostealer with broader remote-access and post-compromise functionality than simple credential theft alone. Separate reporting has also identified a distinct macOS infostealer family using the same name, targeting business users through malicious application bundles and social-engineering lures. Across both ecosystems, MetaStealer is used to harvest sensitive data from compromised hosts and exfiltrate it to attacker-controlled infrastructure.

On Windows, MetaStealer has been delivered through multiple initial-access vectors, including malspam with malicious Excel attachments requiring macro execution, phishing campaigns using OneNote payloads, fake software installers, and malvertising that impersonates legitimate software brands. Observed infection chains have used scripts and staged payload retrieval from public hosting services before establishing persistence and contacting command-and-control infrastructure. Persistence mechanisms reported for Windows variants include scheduled tasks and user logon shell modification. Defense-evasion behavior includes runtime string obfuscation and attempts to weaken Microsoft Defender protections by adding exclusions.

Windows MetaStealer is designed to steal browser data from Chromium-based browsers and Firefox, including cookies and saved passwords, and reporting also attributes theft of files and, in some cases, cryptocurrency-wallet-related data. Technical analyses have recovered references to browser storage artifacts and collection workflows consistent with credential and session theft. Some variants also support keylogging, arbitrary command execution, and hidden remote-control functionality, indicating use beyond pure smash-and-grab theft. Additional analyses describe command-and-control tasking, shellcode-related functionality, SOCKS or backconnect capability, and other post-exploitation features. MetaStealer has also been observed adapting to newer browser protections, including techniques associated with Chromium Application-Bound Encryption bypass via COM-based interaction with browser elevation services.

MetaStealer communications have been linked to structured HTTP-based tasking and collection endpoints, and multiple reports describe the family’s use of domain generation algorithms for command-and-control discovery. Researchers have documented both older pseudo-random domain generation and newer wordlist-based DGA behavior, with gate infrastructure appearing relatively domain-agnostic and relying on consistent ports, URIs, and headers. Obfuscation is a recurring trait in Windows samples, including XOR-based string decoding and encrypted configuration data.

The malware has been associated with criminal distribution as well as use in targeted phishing operations. Reporting has linked MetaStealer to campaigns run by Sticky Werewolf against Russian scientific, industrial, and government-related organizations, alongside other malware used by that actor. MetaStealer has also been cited among infostealer families whose stolen credentials were later abused in follow-on intrusions, including compromises of Snowflake customer environments.

A macOS malware family also tracked as MetaStealer appeared in 2023. That family is a Go-based infostealer distributed in malicious DMG and ZIP lures, often themed around business communications or fake clients. It targets Intel-based macOS systems and has been observed stealing keychain data, saved passwords, and files, with some variants also referencing Telegram and Meta-related data. Its delivery model differs from many macOS stealers by focusing on business-themed social engineering rather than primarily cracked-software lures.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Reconnaissance
  • Session Hijacking
  • Spoofing

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 29, 2026
Last activity
Aug 29, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • NL1

Leading providers

  • LeaseWeb Netherlands B.V.1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
Sticky Werewolf

...стилеры Glory Stealer и MetaStealer (вариация RedLine Stealer).

meta

Unit42 recently tweeted about a campaign starting with a malicious email link that downloads a OneNote file used to drop and execute MetaStealer.

MITRE ATT&CK

MetaStealer in ATT&CK

38 distinct techniques

Reporting

Research mentioning MetaStealer

Aug 5
Malware News

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions - Malware News - Malware Analysis, News and Indicators

Connor Riley Moucka, a 26-year-old Canadian national, pleaded guilty in U.S. federal court for his role in a Snowflake-linked hacking and extortion campaign that compromised at least 165 organizations and exposed data tied to at least 100 million people. Prosecutors said the group used stolen credentials between February and October 2024 to access cloud-hosted customer environments, steal terabytes of sensitive data and billions of files, and extort victims by threatening to publish the information. Reported victims included AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, and LendingTree, with stolen records including banking data, Social Security numbers, passport numbers, driver’s license numbers, and DEA registration numbers. Investigators said the intrusions were not caused by a compromise of Snowflake itself but by previously exposed customer credentials, many traced to infostealer malware infections dating back to 2020. Mandiant found that at least 79.7% of the accounts used in the campaign had prior credential exposure, and observed the attackers using Snowflake’s SnowSight web interface, the SnowSQL CLI, DBeaver Ultimate, and a reconnaissance utility tracked as FROSTBITE to enumerate users, roles, IPs, session IDs, and organization names. Authorities said the conspiracy generated more than $2.5 million in ransom payments, while Moucka separately made about $495,000 selling stolen data on cybercrime forums; he was extradited to the United States and is scheduled to be sentenced on October 27, 2026.

Aug 5
Data Breaches

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions - DataBreaches.Net

Aug 5
Bleeping Computer

Canadian pleads guilty to Snowflake cloud data-theft attacks

Aug 5
Cyberscoop

Snowflake hacker pleads guilty, faces up to 32 years in prison | CyberScoop

Aug 5
The Record Media

Canadian man pleads guilty to Snowflake hacks that led to 165 breaches | The Record from Recorded Future News

Aug 5
Darkwebinformer

Canadian Hacker Pleads Guilty in Cloud Breach Spree Affecting More Than 165 Organizations

Aug 5
Us Department Of Justice

Office of Public Affairs | Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions | United States Department of Justice

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.