Skip to content

MetaStealer

MetaStealer is an information-stealing malware family active since 2022 and commonly described as a derivative of RedLine with additional features and heavier obfuscation.

Profile source: Mallory opens in a new tab

MetaStealer

Family profile

MetaStealer is an information-stealing malware family active since 2022 and commonly described as a derivative of RedLine with additional features and heavier obfuscation. It has been observed primarily on Windows and macOS, with Windows variants implemented in .NET and macOS variants delivered as heavily obfuscated Go-based Mach-O binaries. The malware is designed to harvest sensitive data from compromised systems, including browser credentials, cookies, saved passwords, files, and in some cases cryptocurrency wallet data. Documented Windows capabilities also include keylogging, hidden VNC-style remote access, arbitrary command execution, system reconnaissance, persistence via scheduled tasks, and defense evasion through Microsoft Defender exclusions. Some reporting also links MetaStealer activity to techniques for bypassing Chromium Application-Bound Encryption to recover protected browser secrets.

On Windows, MetaStealer has been observed using encrypted configuration data and runtime string deobfuscation, communicating with command-and-control infrastructure over HTTP using JSON-based tasking. Reported tasking includes browser data theft from Chrome, Edge, and Firefox, command execution, and collection of host information. Persistence has been established through scheduled tasks, and some samples rename themselves and store bot identifiers locally. MetaStealer infrastructure has also been associated with domain generation algorithms, including a newer wordlist-based DGA, while gate servers appear to rely more on transport and protocol characteristics than on any specific domain.

On macOS, MetaStealer emerged during 2023 as a business-focused infostealer distributed through malicious application bundles packaged in DMG or ZIP archives. Social-engineering lures have included fake client project materials and software-themed installers. macOS variants have been observed stealing keychain data, saved passwords, files, and in some cases data associated with Telegram and Meta services. These samples were single-architecture Intel binaries and generally required users to bypass normal Apple trust protections to execute.

Observed delivery methods include malvertising, fake software installers, business-themed lure files, and social-engineering campaigns impersonating legitimate software or services. MetaStealer has been delivered in campaigns involving spoofed tax-related brands, fake AnyDesk installers, and malicious Google Ads impersonating products such as Mozilla Thunderbird and Microsoft Teams. It has also been referenced among infostealers implicated in broader credential-exposure ecosystems, including compromises where previously stolen credentials were later abused against cloud services. MetaStealer is best characterized as a cross-platform commodity infostealer with credential theft, browser data theft, exfiltration, persistence, and post-compromise tasking capabilities.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 10, 2026
Last activity
Aug 10, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • RU1

Leading providers

  • CJSC Kolomna-Sviaz TV1

Samples

Recent associated samples

MITRE ATT&CK

MetaStealer in ATT&CK

27 distinct techniques

Reporting

Research mentioning MetaStealer

Aug 5
Malware News

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions - Malware News - Malware Analysis, News and Indicators

Connor Riley Moucka, a 26-year-old Canadian national, pleaded guilty in U.S. federal court for his role in a Snowflake-linked hacking and extortion campaign that compromised at least 165 organizations and exposed data tied to at least 100 million people. Prosecutors said the group used stolen credentials between February and October 2024 to access cloud-hosted customer environments, steal terabytes of sensitive data and billions of files, and extort victims by threatening to publish the information. Reported victims included AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, and LendingTree, with stolen records including banking data, Social Security numbers, passport numbers, driver’s license numbers, and DEA registration numbers. Investigators said the intrusions were not caused by a compromise of Snowflake itself but by previously exposed customer credentials, many traced to infostealer malware infections dating back to 2020. Mandiant found that at least 79.7% of the accounts used in the campaign had prior credential exposure, and observed the attackers using Snowflake’s SnowSight web interface, the SnowSQL CLI, DBeaver Ultimate, and a reconnaissance utility tracked as FROSTBITE to enumerate users, roles, IPs, session IDs, and organization names. Authorities said the conspiracy generated more than $2.5 million in ransom payments, while Moucka separately made about $495,000 selling stolen data on cybercrime forums; he was extradited to the United States and is scheduled to be sentenced on October 27, 2026.

Aug 5
Data Breaches

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions - DataBreaches.Net

Aug 5
Bleeping Computer

Canadian pleads guilty to Snowflake cloud data-theft attacks

Aug 5
Cyberscoop

Snowflake hacker pleads guilty, faces up to 32 years in prison | CyberScoop

Aug 5
The Record Media

Canadian man pleads guilty to Snowflake hacks that led to 165 breaches | The Record from Recorded Future News

Aug 5
Darkwebinformer

Canadian Hacker Pleads Guilty in Cloud Breach Spree Affecting More Than 165 Organizations

Aug 5
Us Department Of Justice

Office of Public Affairs | Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions | United States Department of Justice

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.