Skip to content

RedLine

RedLine Stealer is a Windows information-stealing malware family written in C# that emerged in early 2020 and became one of the most widely used commodity stealers in the cybercrime ecosystem.

Profile source: Mallory opens in a new tab

RedLine

Family profile

RedLine Stealer is a Windows information-stealing malware family written in C# that emerged in early 2020 and became one of the most widely used commodity stealers in the cybercrime ecosystem. It is commonly sold and deployed as part of malware-as-a-service and pay-per-install operations, and has frequently appeared alongside other crimeware families such as loaders, stealers, miners, and proxy malware. RedLine has been used both for direct theft from individual victims and as an upstream access source for broader intrusions, including enterprise and cloud account compromise.

Its core functionality centers on theft of browser-saved credentials, session cookies, and other sensitive user data. Reported use cases include harvesting credentials later abused to access SaaS platforms, VPNs, cloud file-sharing services, and enterprise identities. RedLine has also been associated with collection of browser data, wallet-related information, and screenshots, making it relevant to both account takeover and financially motivated operations. Stolen session material can enable follow-on abuse without requiring password re-entry or MFA at the time of replay.

RedLine is regularly delivered through opportunistic social-engineering and malware distribution channels rather than bespoke exploitation. Observed delivery vectors include cracked software, fake installers, malicious email attachments, drive-by download chains, and broader bundled malware campaigns. It has also been observed as a payload delivered by third-party loaders and distribution services, including campaigns abusing remote management tooling or gaming-themed lures. In some operations, RedLine was one component of a larger infection set that also established persistence, weakened defenses, enabled proxying, or deployed additional payloads.

The malware has figured prominently in the stealer-log economy. Credentials and session artifacts harvested by RedLine have been resold in underground markets and subsequently used by initial access brokers and intrusion actors. Documented downstream abuse includes compromise of corporate accounts on cloud collaboration and file-sharing platforms and use of infostealer-derived access in larger extortion and intrusion workflows. RedLine also appeared in infrastructure and panel ecosystems hosted by abuse-tolerant providers and was significant enough to be referenced in major law-enforcement disruption efforts, including the dismantling of RedLine and META infrastructure in Operation Magnus in October 2024.

Operationally, sandboxed samples attributed to RedLine have shown host discovery behavior, process enumeration, registry querying, dropped components, and suspicious memory-manipulation or injection-related activity, consistent with stealer execution chains that stage or protect payloads before exfiltration. RedLine has also been observed in campaigns linked to Russian-speaking cybercrime ecosystems and bundled operations such as Operation STANDOFF, where it contributed credential theft within a broader monetization chain.

Capabilities

  • Credential Theft
  • Exfiltration
  • Process Injection
  • Reconnaissance
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 31, 2026
Last activity
Aug 7, 2026
Feed role
C2 / Distribution
Host form
45 IP / 20 hostnames

Leading locations

  • CN12
  • US12
  • NL9
  • DE6
  • RU5
  • HK3
  • FR2
  • KR2
  • PL2
  • CA1
  • CY1
  • GR1

Leading providers

  • CHINA UNICOM China169 Backbone4
  • FEMO IT SOLUTIONS LIMITED4
  • Amazon.com, Inc.3
  • Omegatech LTD3
  • HosterDaddy Private Limited2
  • OVH SAS2

Infrastructure traits

  • Hosting 45
  • Vpn 2
  • Anycast 1
  • Proxy 1

Samples

Recent associated samples

Reported operators

Threat actors

10 named in public reporting
Operation STANDOFF

Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : RedLine Stealer (vol de credentials, MissionID @Tui , C2 : 185.215.113.44:23759 )

NoName057(16)

The RedLine Stealer Trojan is used to spread a malware called Bobik.

LAPSUS$

LAPSUS$ acquired and used the Redline password stealer in their operations.

Amadey

Amadey is a modular Windows botnet sold as MaaS by author "InCrease" on XSS/Exploit forums, active since 2018. It commonly drops Lumma, StealC, RedLine, CoinMiners, and RATs.

UAC-0194

ClearSky researchers observed that this vulnerability has been used to distribute various malware, including Redline Stealer and SparkRAT.

YouTube Ghost Network

Others include StealC, RedLine, Odebug and other Phemedrone variants, and NodeJS loaders and downloaders.

Zestix

Hudson Rock researchers investigated the alleged breaches and found the threat actor relied on distributing infostealers such as RedLine, Lumma, or Vidar... to harvest credentials.

LAUNDRY BEAR

"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."

Storm-0501

"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."

Curious Serpens

"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."

Exploited software

Vulnerabilities linked to RedLine

1 CVEs

MITRE ATT&CK

RedLine in ATT&CK

103 distinct techniques

Techniques

103 techniques
T1078 Valid Accounts T1113 Screen Capture T1555 Credentials from Password Stores T1204 User Execution T1071 Application Layer Protocol T1189 Drive-by Compromise T1539 Steal Web Session Cookie T1105 Ingress Tool Transfer T1005 Data from Local System T1562.001 Disable or Modify Tools T1497 Virtualization/Sandbox Evasion T1041 Exfiltration Over C2 Channel T1071.001 Web Protocols T1082 System Information Discovery T1056 Input Capture T1557 Adversary-in-the-Middle T1555.003 Credentials from Web Browsers T1566 Phishing T1567 Exfiltration Over Web Service T1583.003 Virtual Private Server T1665 Hide Infrastructure T1115 Clipboard Data T1649 Steal or Forge Authentication Certificates T1204.002 Malicious File T1566.002 Spearphishing Link T1055 Process Injection T1059 Command and Scripting Interpreter T1057 Process Discovery T1012 Query Registry T1497.003 Time Based Checks T1498 Network Denial of Service T1560 Archive Collected Data T1583 Acquire Infrastructure T1003 OS Credential Dumping T1566.001 Spearphishing Attachment T1571 Non-Standard Port T1056.001 Keylogging T1036 Masquerading T1566.003 Spearphishing via Service T1588.001 Malware T1598 Phishing for Information T1087.004 Cloud Account T1528 Steal Application Access Token T1608.006 SEO Poisoning T1583.008 Malvertising T1132 Data Encoding T1053.005 Scheduled Task T1059.003 Windows Command Shell T1550 Use Alternate Authentication Material T1027 Obfuscated Files or Information T1110.004 Credential Stuffing T1205 Traffic Signaling T1140 Deobfuscate/Decode Files or Information T1586 Compromise Accounts T1204.001 Malicious Link T1102 Web Service T1552 Unsecured Credentials T1112 Modify Registry T1033 System Owner/User Discovery T1553.002 Code Signing T1614 System Location Discovery T1518.001 Security Software Discovery T1497.001 System Checks T1555.004 Windows Credential Manager T1218.005 Mshta T1059.001 PowerShell T1059.005 Visual Basic T1583.001 Domains T1562 Impair Defenses T1129 Shared Modules T1036.005 Match Legitimate Resource Name or Location T1106 Native API T1622 Debugger Evasion T1195.002 Compromise Software Supply Chain T1573.002 Asymmetric Cryptography T1553.005 Mark-of-the-Web Bypass T1027.013 Encrypted/Encoded File T1587.003 Digital Certificates T1595 Active Scanning T1587.001 Malware T1587 Develop Capabilities T1195 Supply Chain Compromise T1070 Indicator Removal T1218.007 Msiexec T1027.003 Steganography T1518 Software Discovery T1218 System Binary Proxy Execution T1053 Scheduled Task/Job T1614.001 System Language Discovery T1620 Reflective Code Loading T1217 Browser Information Discovery T1556.006 Multi-Factor Authentication T1489 Service Stop T1027.002 Software Packing T1016 System Network Configuration Discovery T1059.011 Lua T1027.010 Command Obfuscation T1087.001 Local Account T1132.001 Standard Encoding T1657 Financial Theft T1480 Execution Guardrails T1133 External Remote Services T1597.002 Purchase Technical Data

Reporting

Research mentioning RedLine

Aug 5
Malware News

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions - Malware News - Malware Analysis, News and Indicators

Connor Riley Moucka, a 26-year-old Canadian national, pleaded guilty in U.S. federal court for his role in a Snowflake-linked hacking and extortion campaign that compromised at least 165 organizations and exposed data tied to at least 100 million people. Prosecutors said the group used stolen credentials between February and October 2024 to access cloud-hosted customer environments, steal terabytes of sensitive data and billions of files, and extort victims by threatening to publish the information. Reported victims included AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, and LendingTree, with stolen records including banking data, Social Security numbers, passport numbers, driver’s license numbers, and DEA registration numbers. Investigators said the intrusions were not caused by a compromise of Snowflake itself but by previously exposed customer credentials, many traced to infostealer malware infections dating back to 2020. Mandiant found that at least 79.7% of the accounts used in the campaign had prior credential exposure, and observed the attackers using Snowflake’s SnowSight web interface, the SnowSQL CLI, DBeaver Ultimate, and a reconnaissance utility tracked as FROSTBITE to enumerate users, roles, IPs, session IDs, and organization names. Authorities said the conspiracy generated more than $2.5 million in ransom payments, while Moucka separately made about $495,000 selling stolen data on cybercrime forums; he was extradited to the United States and is scheduled to be sentenced on October 27, 2026.

Aug 5
Data Breaches

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions - DataBreaches.Net

Aug 5
Bleeping Computer

Canadian pleads guilty to Snowflake cloud data-theft attacks

Aug 5
Cyberscoop

Snowflake hacker pleads guilty, faces up to 32 years in prison | CyberScoop

Aug 5
The Record Media

Canadian man pleads guilty to Snowflake hacks that led to 165 breaches | The Record from Recorded Future News

Aug 5
Darkwebinformer

Canadian Hacker Pleads Guilty in Cloud Breach Spree Affecting More Than 165 Organizations

Aug 5
Us Department Of Justice

Office of Public Affairs | Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions | United States Department of Justice

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.