RedLine Stealer is a Windows information-stealing malware family first observed in March 2020 and distributed through a malware-as-a-service model. It harvests browser-stored usernames and passwords, session cookies and authentication tokens, autocomplete data, credit card information, instant messages, cryptocurrency wallet information, and FTP client data. It also inventories compromised systems, collecting operating system, hardware, running-process, and language information. Additional functionality includes file uploads and downloads and command execution. RedLine has been associated with Windows DiskCleanup scheduled-task hijacking to bypass User Account Control.
Distribution methods include phishing, malicious Google advertisements, weaponized Microsoft Office documents, fake Windows 11 upgrade tools, cracked-software bundles, and malicious Windows shortcuts. SmokeLoader has also delivered RedLine as a secondary payload. Its infections affect both personal and corporate endpoints, exposing credentials and authenticated sessions for subsequent account takeover and organizational compromise.
RedLine is used by cybercriminals and initial-access brokers, with stolen logs traded through underground marketplaces and messaging platforms. Lapsus$ has used it to obtain passwords and session tokens. Stolen session material can enable authenticated-session replay without completing a new multifactor authentication challenge. Credentials exposed through RedLine infections have also been implicated in subsequent ransomware access. In late October 2024, international law enforcement disrupted infrastructure supporting RedLine and Meta Stealer and announced charges against a RedLine developer and administrator.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2024-1709 (CWE-288) — Authentication Bypass Using Alternate Path or Channel. Base CVSS score of 10, indicating “Critical”.
CVE-2024-1708 (CWE-22) — Improper Limitation of a Pathname to a Restricted Directory (“Path Traversal”). Base CVSS score of 8.4, still considered “High Priority”.
Microsoft created a security patch for Windows systems to fix the vulnerability, giving it the CVE identifier CVE-2024-43451. The security patch was published on November 12th, 2024. | The other files detected exploiting the new vulnerability followed a similar attack scenario that ended with the installation of Redline Stealer malware.
The embedded file with a randomized file name exploits a particular vulnerability —CVE-2017-11882—to execute malicious code to deliver and execute malware on a victim’s device. | Redline (also known as Redline Stealer) is a commercial malware family designed to collect sensitive information from infected devices, such as saved credentials, autocomplete data, credit card information, and more.
18 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Lapsus$ Group” has used “RedLine” to obtain passwords and session tokens.
The threat actor, tracked by Mandiant as UNC5587, used infostealer malware such as RedLine, Lumma, and Vidar to harvest credentials from infected employee devices.
2020 (or earlier): The Infection The campaign operator gets infected by RedLine Stealer. Admin credentials are exfiltrated to the Dark Web.
2020 (or earlier): The Infection The campaign operator gets infected by RedLine Stealer. Admin credentials are exfiltrated to the Dark Web.
In many cases, ZingoStealer also delivers additional malware such as RedLine Stealer and the XMRig cryptocurrency mining malware to victims.
Batloader has been observed to drop several malware payloads, such as Ursnif, Vidar, Bumbleloader, RedLine Stealer, ZLoader, Cobalt Strike, and SmokeLoader.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
1,532 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cited as credential-stealing malware used in earlier Snowflake customer breaches. The article describes these infostealers as collecting browser cookies, saved passwords, and CLI configurations. RedLine is not confirmed as involved in the ASOS incident.
Cited as an example of an infostealer that can harvest browser vaults, session cookies, Discord tokens, and saved SSH/FTP credentials and send them to attacker-controlled infrastructure. The content does not establish that RedLine was used in this breach.
An information stealer described as extracting browser cookies, authentication tokens and session IDs. The article discusses session theft as a hypothetical route to Microsoft's X account compromise; it does not establish that RedLine was involved.
Infostealer cité parmi les principales familles impliquées dans le vol de credentials cloud, de code et d'outils d'IA.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.