Last seven days
- First activity
- Aug 29, 2026
- Last activity
- Aug 29, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
MetaStealer is an information-stealing malware family that emerged in 2022 and has been widely described as a derivative or variation of RedLine Stealer.
Profile source: Mallory opens in a new tabMetaStealer
MetaStealer is an information-stealing malware family that emerged in 2022 and has been widely described as a derivative or variation of RedLine Stealer. It is primarily associated with Windows infections, where it has been observed as a commodity infostealer with broader remote-access and post-compromise functionality than simple credential theft alone. Separate reporting has also identified a distinct macOS infostealer family using the same name, targeting business users through malicious application bundles and social-engineering lures. Across both ecosystems, MetaStealer is used to harvest sensitive data from compromised hosts and exfiltrate it to attacker-controlled infrastructure.
On Windows, MetaStealer has been delivered through multiple initial-access vectors, including malspam with malicious Excel attachments requiring macro execution, phishing campaigns using OneNote payloads, fake software installers, and malvertising that impersonates legitimate software brands. Observed infection chains have used scripts and staged payload retrieval from public hosting services before establishing persistence and contacting command-and-control infrastructure. Persistence mechanisms reported for Windows variants include scheduled tasks and user logon shell modification. Defense-evasion behavior includes runtime string obfuscation and attempts to weaken Microsoft Defender protections by adding exclusions.
Windows MetaStealer is designed to steal browser data from Chromium-based browsers and Firefox, including cookies and saved passwords, and reporting also attributes theft of files and, in some cases, cryptocurrency-wallet-related data. Technical analyses have recovered references to browser storage artifacts and collection workflows consistent with credential and session theft. Some variants also support keylogging, arbitrary command execution, and hidden remote-control functionality, indicating use beyond pure smash-and-grab theft. Additional analyses describe command-and-control tasking, shellcode-related functionality, SOCKS or backconnect capability, and other post-exploitation features. MetaStealer has also been observed adapting to newer browser protections, including techniques associated with Chromium Application-Bound Encryption bypass via COM-based interaction with browser elevation services.
MetaStealer communications have been linked to structured HTTP-based tasking and collection endpoints, and multiple reports describe the family’s use of domain generation algorithms for command-and-control discovery. Researchers have documented both older pseudo-random domain generation and newer wordlist-based DGA behavior, with gate infrastructure appearing relatively domain-agnostic and relying on consistent ports, URIs, and headers. Obfuscation is a recurring trait in Windows samples, including XOR-based string decoding and encrypted configuration data.
The malware has been associated with criminal distribution as well as use in targeted phishing operations. Reporting has linked MetaStealer to campaigns run by Sticky Werewolf against Russian scientific, industrial, and government-related organizations, alongside other malware used by that actor. MetaStealer has also been cited among infostealer families whose stolen credentials were later abused in follow-on intrusions, including compromises of Snowflake customer environments.
A macOS malware family also tracked as MetaStealer appeared in 2023. That family is a Go-based infostealer distributed in malicious DMG and ZIP lures, often themed around business communications or fake clients. It targets Intel-based macOS systems and has been observed stealing keychain data, saved passwords, and files, with some variants also referencing Telegram and Meta-related data. Its delivery model differs from many macOS stealers by focusing on business-themed social engineering rather than primarily cracked-software lures.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
...стилеры Glory Stealer и MetaStealer (вариация RedLine Stealer).
Unit42 recently tweeted about a campaign starting with a malicious email link that downloads a OneNote file used to drop and execute MetaStealer.
MITRE ATT&CK
Reporting
Connor Riley Moucka, a 26-year-old Canadian national, pleaded guilty in U.S. federal court for his role in a Snowflake-linked hacking and extortion campaign that compromised at least 165 organizations and exposed data tied to at least 100 million people. Prosecutors said the group used stolen credentials between February and October 2024 to access cloud-hosted customer environments, steal terabytes of sensitive data and billions of files, and extort victims by threatening to publish the information. Reported victims included AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, and LendingTree, with stolen records including banking data, Social Security numbers, passport numbers, driver’s license numbers, and DEA registration numbers. Investigators said the intrusions were not caused by a compromise of Snowflake itself but by previously exposed customer credentials, many traced to infostealer malware infections dating back to 2020. Mandiant found that at least 79.7% of the accounts used in the campaign had prior credential exposure, and observed the attackers using Snowflake’s SnowSight web interface, the SnowSQL CLI, DBeaver Ultimate, and a reconnaissance utility tracked as FROSTBITE to enumerate users, roles, IPs, session IDs, and organization names. Authorities said the conspiracy generated more than $2.5 million in ransom payments, while Moucka separately made about $495,000 selling stolen data on cybercrime forums; he was extradited to the United States and is scheduled to be sentenced on October 27, 2026.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.