Last seven days
- First activity
- Aug 22, 2026
- Last activity
- Aug 29, 2026
- Feed role
- C2 / Distribution
- Host form
- 83 IP / 30 hostnames
RedLine Stealer is a Windows information-stealing malware family that emerged in 2020 and has been widely operated as a malware-as-a-service offering.
Profile source: Mallory opens in a new tabRedLine
RedLine Stealer is a Windows information-stealing malware family that emerged in 2020 and has been widely operated as a malware-as-a-service offering. It is commonly distributed through social-engineering lures and commodity crimeware delivery chains, including cracked software, fake game cheats, trojanized applications, spam campaigns, and malicious Microsoft OneNote attachments. It has also appeared in campaigns using topical lures such as coronavirus-themed messages.
RedLine is designed to harvest a broad range of victim data. Its core functionality includes theft of saved browser credentials, cookies, autocomplete data, payment card information, and other browser-stored secrets from Chromium- and Gecko-based browsers. It also targets cryptocurrency wallets, Discord tokens, Telegram session data, Steam-related files, FileZilla connection data, and credentials or configuration data from VPN and other desktop applications. In addition to credential and application data theft, RedLine performs host profiling by collecting system metadata such as usernames, installed software, running processes, hardware details, language settings, and installed antivirus products. Some variants also capture screenshots and search the filesystem for documents and other files of interest.
Beyond passive collection, RedLine supports remote tasking from command-and-control infrastructure. Documented capabilities include downloading additional payloads, executing files or shell commands, and opening links, making it useful both as a standalone infostealer and as an enabler for broader post-compromise activity. It has been associated with follow-on malware delivery and has been used by criminal actors and initial access brokers to obtain credentials later leveraged in ransomware and other intrusions. Reporting has also linked its use to actors such as LAPSUS$.
Operationally, RedLine has been observed using Windows-native and .NET functionality for payload staging, decryption, and communications, and some samples communicate over SOAP/HTTP. It is notable for broad credential and wallet targeting, flexible operator tasking, and frequent use in commodity cybercrime ecosystems.
C2 tracking
Derp observations, rolling seven-day window
Samples
1ab38c4f49f7fbfefe9665466e276c5b6181f201ca54f74666030e38b9954a18 1cd56e19b8a4e21a6ea73949631ef80e8ba460d5ad527589e2c58964d2710054 5e4cb29836187e495329e0374acba583cefb50a9342b82ea86012d87b3ac9881 a87312122ffb2232249ac5cecf2418068c6d3bd7f33abd0b8dfce2d456e8e1af f9f09fbf412e4b4465dc900e7b28c14fc052c46aed1abcf6b0889ccc9ec765b7 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 30daba44a4a25ff5750508613f897057a55337458f19b562e2ed1172c77e626b 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 7126b9932dc0cdfe751340edfa7c4a14b69262eb1afd0530e6d1fdb2e25986dd 73ddf0df4e9e3866511ef9eae421b11615b81491d0db1d4a7ed19441e368ecef Reported operators
Starting in mid-March 2022, eSentire observed an increase in the deployment of Redline Stealer malware. Redline Stealer is an information stealing malware that was first identified in early 2020.
2020 (or earlier): The Infection The campaign operator gets infected by RedLine Stealer. Admin credentials are exfiltrated to the Dark Web.
2020 (or earlier): The Infection The campaign operator gets infected by RedLine Stealer. Admin credentials are exfiltrated to the Dark Web.
In many cases, ZingoStealer also delivers additional malware such as RedLine Stealer and the XMRig cryptocurrency mining malware to victims.
Batloader has been observed to drop several malware payloads, such as Ursnif, Vidar, Bumbleloader, RedLine Stealer, ZLoader, Cobalt Strike, and SmokeLoader.
When KELA first observed the threat actor “_META_” offering a new stealer, it was marketed as having the same functionality and panel as RedLine Stealer.
PowerShellコードによって実行されるマルウェアのうち、Zeip.exe は .NET製のダウンローダであり、実行されるとRedline Stealerをダウンロード・実行します。Redline Stealerは端末内に保存された機密情報を窃取します。
In last weeks’ campaigns Sekoia observed, the following malware families were actively distributed by PrivateLoader payloads: Information stealers: Redline...
Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : RedLine Stealer (vol de credentials, MissionID @Tui , C2 : 185.215.113.44:23759 )
The RedLine Stealer Trojan is used to spread a malware called Bobik.
Amadey is a modular Windows botnet sold as MaaS by author "InCrease" on XSS/Exploit forums, active since 2018. It commonly drops Lumma, StealC, RedLine, CoinMiners, and RATs.
ClearSky researchers observed that this vulnerability has been used to distribute various malware, including Redline Stealer and SparkRAT.
Others include StealC, RedLine, Odebug and other Phemedrone variants, and NodeJS loaders and downloaders.
Hudson Rock researchers investigated the alleged breaches and found the threat actor relied on distributing infostealers such as RedLine, Lumma, or Vidar... to harvest credentials.
"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."
"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."
"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."
Exploited software
MITRE ATT&CK
Reporting
A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.
Connor Riley Moucka, a 26-year-old Canadian national, pleaded guilty in U.S. federal court for his role in a Snowflake-linked hacking and extortion campaign that compromised at least 165 organizations and exposed data tied to at least 100 million people. Prosecutors said the group used stolen credentials between February and October 2024 to access cloud-hosted customer environments, steal terabytes of sensitive data and billions of files, and extort victims by threatening to publish the information. Reported victims included AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, and LendingTree, with stolen records including banking data, Social Security numbers, passport numbers, driver’s license numbers, and DEA registration numbers. Investigators said the intrusions were not caused by a compromise of Snowflake itself but by previously exposed customer credentials, many traced to infostealer malware infections dating back to 2020. Mandiant found that at least 79.7% of the accounts used in the campaign had prior credential exposure, and observed the attackers using Snowflake’s SnowSight web interface, the SnowSQL CLI, DBeaver Ultimate, and a reconnaissance utility tracked as FROSTBITE to enumerate users, roles, IPs, session IDs, and organization names. Authorities said the conspiracy generated more than $2.5 million in ransom payments, while Moucka separately made about $495,000 selling stolen data on cybercrime forums; he was extradited to the United States and is scheduled to be sentenced on October 27, 2026.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.