META is a cybercriminal actor associated with the META infostealer, a malware offering marketed as having functionality and operator infrastructure similar to RedLine Stealer. The actor has been linked to credential theft operations focused on harvesting browser-stored data, including passwords, cookies, and related encrypted browser artifacts. Technical analysis of MetaStealer samples shows heavy obfuscation, encoded strings, and the use of a domain generation algorithm for command-and-control discovery, indicating an effort to improve resilience and hinder analysis. Recovered functionality from analyzed samples indicates capabilities beyond basic credential theft. In addition to collecting browser data, MetaStealer has shown support for SOCKS-style proxying, backconnect behavior, shellcode execution, task-based command handling, and firewall rule manipulation. Campaign reporting also tied MetaStealer delivery to malicious email lures that led to execution of the stealer, demonstrating phishing-based initial access. These characteristics place the actor in the broader infostealer ecosystem, with post-compromise capabilities extending into general remote tasking and operational flexibility. META is also notable for its operational overlap in branding and market positioning with RedLine-related criminal activity. Law enforcement reporting has stated that authorities obtained complete access to infrastructure behind both the RedLine and META infostealers, underscoring the actor’s role in established cybercrime malware operations rather than state-directed espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actor associated with offering and operating MetaStealer, a credential-stealing malware family that also appears to support expanded capabilities such as backconnect, SOCKS functionality, firewall hole-punching, and shellcode detonation.
Infostealer malware used for credential theft and data exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.