Last seven days
- First activity
- Jul 31, 2026
- Last activity
- Aug 7, 2026
- Feed role
- C2 / Distribution
- Host form
- 45 IP / 20 hostnames
RedLine Stealer is a Windows information-stealing malware family written in C# that emerged in early 2020 and became one of the most widely used commodity stealers in the cybercrime ecosystem.
Profile source: Mallory opens in a new tabRedLine
RedLine Stealer is a Windows information-stealing malware family written in C# that emerged in early 2020 and became one of the most widely used commodity stealers in the cybercrime ecosystem. It is commonly sold and deployed as part of malware-as-a-service and pay-per-install operations, and has frequently appeared alongside other crimeware families such as loaders, stealers, miners, and proxy malware. RedLine has been used both for direct theft from individual victims and as an upstream access source for broader intrusions, including enterprise and cloud account compromise.
Its core functionality centers on theft of browser-saved credentials, session cookies, and other sensitive user data. Reported use cases include harvesting credentials later abused to access SaaS platforms, VPNs, cloud file-sharing services, and enterprise identities. RedLine has also been associated with collection of browser data, wallet-related information, and screenshots, making it relevant to both account takeover and financially motivated operations. Stolen session material can enable follow-on abuse without requiring password re-entry or MFA at the time of replay.
RedLine is regularly delivered through opportunistic social-engineering and malware distribution channels rather than bespoke exploitation. Observed delivery vectors include cracked software, fake installers, malicious email attachments, drive-by download chains, and broader bundled malware campaigns. It has also been observed as a payload delivered by third-party loaders and distribution services, including campaigns abusing remote management tooling or gaming-themed lures. In some operations, RedLine was one component of a larger infection set that also established persistence, weakened defenses, enabled proxying, or deployed additional payloads.
The malware has figured prominently in the stealer-log economy. Credentials and session artifacts harvested by RedLine have been resold in underground markets and subsequently used by initial access brokers and intrusion actors. Documented downstream abuse includes compromise of corporate accounts on cloud collaboration and file-sharing platforms and use of infostealer-derived access in larger extortion and intrusion workflows. RedLine also appeared in infrastructure and panel ecosystems hosted by abuse-tolerant providers and was significant enough to be referenced in major law-enforcement disruption efforts, including the dismantling of RedLine and META infrastructure in Operation Magnus in October 2024.
Operationally, sandboxed samples attributed to RedLine have shown host discovery behavior, process enumeration, registry querying, dropped components, and suspicious memory-manipulation or injection-related activity, consistent with stealer execution chains that stage or protect payloads before exfiltration. RedLine has also been observed in campaigns linked to Russian-speaking cybercrime ecosystems and bundled operations such as Operation STANDOFF, where it contributed credential theft within a broader monetization chain.
C2 tracking
Derp observations, rolling seven-day window
Samples
4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 6747147c5ba29975a557d88cd22114478890a0a0a613f36512dcb730e4efe965 944a6ff7edb3991a3f60e19d26f23ad21054adc53109cfcdbb5d101a84a7971b dd17e871204619a3de34126e366221b64e684ec13e24dfc871698abe343acbff fbf4ef28c4b49c6304d23a738afabf8981590eae8585834bf24e3c7e87163c1a 2f029858b8ecca8fb6c156eb2d046a2463e8b67d356c1003e5567339681a71be 4fe508025770c53e0717b524175f079ee23443a4ed909a36be04ee7522e7e055 9bb943340f1b6bf6cff15334ab9b0ab32740455f50f76a779f1735445cb521ae ed7b43af39b111ebcfd376a6cd5690bfe6523f053c5e96c136fb8df887f8f21c 07f53dbaccf650bf676c1352c6887edf10f3e8e790c8367b892c06a062ca1950 Reported operators
Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : RedLine Stealer (vol de credentials, MissionID @Tui , C2 : 185.215.113.44:23759 )
The RedLine Stealer Trojan is used to spread a malware called Bobik.
LAPSUS$ acquired and used the Redline password stealer in their operations.
Amadey is a modular Windows botnet sold as MaaS by author "InCrease" on XSS/Exploit forums, active since 2018. It commonly drops Lumma, StealC, RedLine, CoinMiners, and RATs.
ClearSky researchers observed that this vulnerability has been used to distribute various malware, including Redline Stealer and SparkRAT.
Others include StealC, RedLine, Odebug and other Phemedrone variants, and NodeJS loaders and downloaders.
Hudson Rock researchers investigated the alleged breaches and found the threat actor relied on distributing infostealers such as RedLine, Lumma, or Vidar... to harvest credentials.
"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."
"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."
"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."
Exploited software
MITRE ATT&CK
Reporting
Connor Riley Moucka, a 26-year-old Canadian national, pleaded guilty in U.S. federal court for his role in a Snowflake-linked hacking and extortion campaign that compromised at least 165 organizations and exposed data tied to at least 100 million people. Prosecutors said the group used stolen credentials between February and October 2024 to access cloud-hosted customer environments, steal terabytes of sensitive data and billions of files, and extort victims by threatening to publish the information. Reported victims included AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, and LendingTree, with stolen records including banking data, Social Security numbers, passport numbers, driver’s license numbers, and DEA registration numbers. Investigators said the intrusions were not caused by a compromise of Snowflake itself but by previously exposed customer credentials, many traced to infostealer malware infections dating back to 2020. Mandiant found that at least 79.7% of the accounts used in the campaign had prior credential exposure, and observed the attackers using Snowflake’s SnowSight web interface, the SnowSQL CLI, DBeaver Ultimate, and a reconnaissance utility tracked as FROSTBITE to enumerate users, roles, IPs, session IDs, and organization names. Authorities said the conspiracy generated more than $2.5 million in ransom payments, while Moucka separately made about $495,000 selling stolen data on cybercrime forums; he was extradited to the United States and is scheduled to be sentenced on October 27, 2026.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.