Skip to content

RedLine

RedLine Stealer is a Windows information-stealing malware family that emerged in 2020 and has been widely operated as a malware-as-a-service offering.

Profile source: Mallory opens in a new tab

RedLine

Family profile

RedLine Stealer is a Windows information-stealing malware family that emerged in 2020 and has been widely operated as a malware-as-a-service offering. It is commonly distributed through social-engineering lures and commodity crimeware delivery chains, including cracked software, fake game cheats, trojanized applications, spam campaigns, and malicious Microsoft OneNote attachments. It has also appeared in campaigns using topical lures such as coronavirus-themed messages.

RedLine is designed to harvest a broad range of victim data. Its core functionality includes theft of saved browser credentials, cookies, autocomplete data, payment card information, and other browser-stored secrets from Chromium- and Gecko-based browsers. It also targets cryptocurrency wallets, Discord tokens, Telegram session data, Steam-related files, FileZilla connection data, and credentials or configuration data from VPN and other desktop applications. In addition to credential and application data theft, RedLine performs host profiling by collecting system metadata such as usernames, installed software, running processes, hardware details, language settings, and installed antivirus products. Some variants also capture screenshots and search the filesystem for documents and other files of interest.

Beyond passive collection, RedLine supports remote tasking from command-and-control infrastructure. Documented capabilities include downloading additional payloads, executing files or shell commands, and opening links, making it useful both as a standalone infostealer and as an enabler for broader post-compromise activity. It has been associated with follow-on malware delivery and has been used by criminal actors and initial access brokers to obtain credentials later leveraged in ransomware and other intrusions. Reporting has also linked its use to actors such as LAPSUS$.

Operationally, RedLine has been observed using Windows-native and .NET functionality for payload staging, decryption, and communications, and some samples communicate over SOAP/HTTP. It is notable for broad credential and wallet targeting, flexible operator tasking, and frequent use in commodity cybercrime ecosystems.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 22, 2026
Last activity
Aug 29, 2026
Feed role
C2 / Distribution
Host form
83 IP / 30 hostnames

Leading locations

  • US24
  • CN19
  • DE17
  • NL11
  • RU8
  • KR5
  • FI4
  • HK4
  • PL4
  • AM2
  • JP2
  • SG2

Leading providers

  • FEMO IT SOLUTIONS LIMITED10
  • Cloudflare, Inc.6
  • CHINA UNICOM China169 Backbone4
  • Hangzhou Alibaba Advertising Co.,Ltd.4
  • Amazon.com, Inc.3
  • HosterDaddy Private Limited3

Infrastructure traits

  • Hosting 89
  • Anycast 7

Samples

Recent associated samples

Reported operators

Threat actors

17 named in public reporting
LAPSUS$

Starting in mid-March 2022, eSentire observed an increase in the deployment of Redline Stealer malware. Redline Stealer is an information stealing malware that was first identified in early 2020.

Lazarus

2020 (or earlier): The Infection The campaign operator gets infected by RedLine Stealer. Admin credentials are exfiltrated to the Dark Web.

APT38

2020 (or earlier): The Infection The campaign operator gets infected by RedLine Stealer. Admin credentials are exfiltrated to the Dark Web.

Haskers Gang

In many cases, ZingoStealer also delivers additional malware such as RedLine Stealer and the XMRig cryptocurrency mining malware to victims.

Water Minyades

Batloader has been observed to drop several malware payloads, such as Ursnif, Vidar, Bumbleloader, RedLine Stealer, ZLoader, Cobalt Strike, and SmokeLoader.

meta

When KELA first observed the threat actor “_META_” offering a new stealer, it was marketed as having the same functionality and panel as RedLine Stealer.

SteelClover

PowerShellコードによって実行されるマルウェアのうち、Zeip.exe は .NET製のダウンローダであり、実行されるとRedline Stealerをダウンロード・実行します。Redline Stealerは端末内に保存された機密情報を窃取します。

ruzki

In last weeks’ campaigns Sekoia observed, the following malware families were actively distributed by PrivateLoader payloads: Information stealers: Redline...

Operation STANDOFF

Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : RedLine Stealer (vol de credentials, MissionID @Tui , C2 : 185.215.113.44:23759 )

NoName057(16)

The RedLine Stealer Trojan is used to spread a malware called Bobik.

Amadey

Amadey is a modular Windows botnet sold as MaaS by author "InCrease" on XSS/Exploit forums, active since 2018. It commonly drops Lumma, StealC, RedLine, CoinMiners, and RATs.

UAC-0194

ClearSky researchers observed that this vulnerability has been used to distribute various malware, including Redline Stealer and SparkRAT.

YouTube Ghost Network

Others include StealC, RedLine, Odebug and other Phemedrone variants, and NodeJS loaders and downloaders.

Zestix

Hudson Rock researchers investigated the alleged breaches and found the threat actor relied on distributing infostealers such as RedLine, Lumma, or Vidar... to harvest credentials.

LAUNDRY BEAR

"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."

Storm-0501

"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."

Curious Serpens

"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."

Exploited software

Vulnerabilities linked to RedLine

2 CVEs

MITRE ATT&CK

RedLine in ATT&CK

89 distinct techniques

Techniques

89 techniques
T1012 Query Registry T1204.002 Malicious File T1027.013 Encrypted/Encoded File T1113 Screen Capture T1083 File and Directory Discovery T1082 System Information Discovery T1140 Deobfuscate/Decode Files or Information T1033 System Owner/User Discovery T1539 Steal Web Session Cookie T1059.003 Windows Command Shell T1213 Data from Information Repositories T1204 User Execution T1055 Process Injection T1583 Acquire Infrastructure T1566.001 Spearphishing Attachment T1566.002 Spearphishing Link T1555 Credentials from Password Stores T1059 Command and Scripting Interpreter T1071 Application Layer Protocol T1005 Data from Local System T1036 Masquerading T1105 Ingress Tool Transfer T1566 Phishing T1189 Drive-by Compromise T1057 Process Discovery T1649 Steal or Forge Authentication Certificates T1078 Valid Accounts T1497.001 System Checks T1555.003 Credentials from Web Browsers T1041 Exfiltration Over C2 Channel T1588.001 Malware T1518.001 Security Software Discovery T1571 Non-Standard Port T1497.003 Time Based Checks T1547.001 Registry Run Keys / Startup Folder T1218.011 Rundll32 T1562.001 Disable or Modify Tools T1106 Native API T1115 Clipboard Data T1497 Virtualization/Sandbox Evasion T1560 Archive Collected Data T1562 Impair Defenses T1003 OS Credential Dumping T1552 Unsecured Credentials T1055.012 Process Hollowing T1518 Software Discovery T1059.001 PowerShell T1567 Exfiltration Over Web Service T1070 Indicator Removal T1059.006 Python T1547 Boot or Logon Autostart Execution T1560.001 Archive via Utility T1548.002 Bypass User Account Control T1071.001 Web Protocols T1027 Obfuscated Files or Information T1129 Shared Modules T1543.003 Windows Service T1112 Modify Registry T1070.006 Timestomp T1053 Scheduled Task/Job T1222 File and Directory Permissions Modification T1134 Access Token Manipulation T1059.007 JavaScript T1176 Software Extensions T1553.002 Code Signing T1218 System Binary Proxy Execution T1218.003 CMSTP T1583.001 Domains T1027.007 Dynamic API Resolution T1203 Exploitation for Client Execution T1564.003 Hidden Window T1132 Data Encoding T1095 Non-Application Layer Protocol T1204.001 Malicious Link T1027.009 Embedded Payloads T1620 Reflective Code Loading T1056 Input Capture T1059.005 Visual Basic T1053.005 Scheduled Task T1119 Automated Collection T1656 Impersonation T1027.002 Software Packing T1543 Create or Modify System Process T1557 Adversary-in-the-Middle T1583.003 Virtual Private Server T1665 Hide Infrastructure T1498 Network Denial of Service T1056.001 Keylogging T1566.003 Spearphishing via Service

Reporting

Research mentioning RedLine

Aug 15
Github Web

GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub

A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

Aug 5
Malware News

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions - Malware News - Malware Analysis, News and Indicators

Connor Riley Moucka, a 26-year-old Canadian national, pleaded guilty in U.S. federal court for his role in a Snowflake-linked hacking and extortion campaign that compromised at least 165 organizations and exposed data tied to at least 100 million people. Prosecutors said the group used stolen credentials between February and October 2024 to access cloud-hosted customer environments, steal terabytes of sensitive data and billions of files, and extort victims by threatening to publish the information. Reported victims included AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, and LendingTree, with stolen records including banking data, Social Security numbers, passport numbers, driver’s license numbers, and DEA registration numbers. Investigators said the intrusions were not caused by a compromise of Snowflake itself but by previously exposed customer credentials, many traced to infostealer malware infections dating back to 2020. Mandiant found that at least 79.7% of the accounts used in the campaign had prior credential exposure, and observed the attackers using Snowflake’s SnowSight web interface, the SnowSQL CLI, DBeaver Ultimate, and a reconnaissance utility tracked as FROSTBITE to enumerate users, roles, IPs, session IDs, and organization names. Authorities said the conspiracy generated more than $2.5 million in ransom payments, while Moucka separately made about $495,000 selling stolen data on cybercrime forums; he was extradited to the United States and is scheduled to be sentenced on October 27, 2026.

Aug 5
Data Breaches

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions - DataBreaches.Net

Aug 5
Bleeping Computer

Canadian pleads guilty to Snowflake cloud data-theft attacks

Aug 5
Cyberscoop

Snowflake hacker pleads guilty, faces up to 32 years in prison | CyberScoop

Aug 5
The Record Media

Canadian man pleads guilty to Snowflake hacks that led to 165 breaches | The Record from Recorded Future News

Aug 5
Darkwebinformer

Canadian Hacker Pleads Guilty in Cloud Breach Spree Affecting More Than 165 Organizations

Aug 5
Us Department Of Justice

Office of Public Affairs | Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions | United States Department of Justice

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.