RedLine Stealer is a Windows information-stealing malware family widely sold and operated as a Malware-as-a-Service offering in cybercriminal ecosystems. It is designed to harvest sensitive data from infected systems, especially credentials and browser-stored information such as saved passwords, autocomplete data, payment card details, cookies, and cryptocurrency wallet data. RedLine also performs host profiling by collecting system and user information and has been reported to enumerate installed security software and gather details related to VPN, FTP, chat, and other applications.
Beyond theft of locally stored data, RedLine can communicate with command-and-control infrastructure to exfiltrate collected information and receive further instructions. Reported functionality includes execution of arbitrary commands and additional payloads, making it useful both as a standalone infostealer and as part of broader intrusion chains. It has been observed as a payload delivered by other malware and loaders including BatLoader, SmokeLoader, Amadey, and PrivateLoader, and it has also been used by criminal actors such as LAPSUS$.
Distribution has been documented through multiple social-engineering and malware-delivery channels. Observed vectors include spam and phishing campaigns, Microsoft OneNote attachment campaigns, trojanized or cracked software, fake game cheats and hacks, fake software installers, malicious download pages, and themed lures such as COVID-19 messaging. RedLine has repeatedly appeared in commodity cybercrime operations targeting a broad victim base rather than a single sector, though infections have been reported across enterprise, consumer, industrial, and cryptocurrency-focused contexts.
The malware is closely associated with credential theft from web browsers and theft of financial and cryptocurrency-related data, and it remains one of the more recognizable commodity stealers in the cybercrime landscape.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Microsoft created a security patch for Windows systems to fix the vulnerability, giving it the CVE identifier CVE-2024-43451. The security patch was published on November 12th, 2024. | The other files detected exploiting the new vulnerability followed a similar attack scenario that ended with the installation of Redline Stealer malware.
The embedded file with a randomized file name exploits a particular vulnerability —CVE-2017-11882—to execute malicious code to deliver and execute malware on a victim’s device. | Redline (also known as Redline Stealer) is a commercial malware family designed to collect sensitive information from infected devices, such as saved credentials, autocomplete data, credit card information, and more.
15 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
RedLine Stealer was designed to steal sensitive information from web browsers, including credit card details, saved credentials, and autocomplete data.
In many cases, ZingoStealer also delivers additional malware such as RedLine Stealer and the XMRig cryptocurrency mining malware to victims.
Batloader has been observed to drop several malware payloads, such as Ursnif, Vidar, Bumbleloader, RedLine Stealer, ZLoader, Cobalt Strike, and SmokeLoader.
When KELA first observed the threat actor “_META_” offering a new stealer, it was marketed as having the same functionality and panel as RedLine Stealer.
PowerShellコードによって実行されるマルウェアのうち、Zeip.exe は .NET製のダウンローダであり、実行されるとRedline Stealerをダウンロード・実行します。Redline Stealerは端末内に保存された機密情報を窃取します。
In last weeks’ campaigns Sekoia observed, the following malware families were actively distributed by PrivateLoader payloads: Information stealers: Redline...
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The use of Microsoft OneNote documents to deliver malware via email is increasing. Multiple cybercriminal threat actors are using OneNote documents to deliver malware.
RegAsm.exe 프로세스를 실행 후 해당 프로세스에 할로잉되어 동작한다. ... nslookup.exe를 실행 후 프로세스 할로잉하여 동작한다.
Mitre ATT&CK Tactics And Techniques Associated to This Collection ... Rundll32 T1218.011
RedLine is currently the most widely deployed information stealer capable of harvesting victims' passwords, browser cookies, credit card info, and cryptocurrency wallet info.
“History” contained the Edge Browser history, “Login Data” contained the Edge Browser login data, “Cookies” contained the Edge browser cookies...
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
Mitre ATT&CK Tactics And Techniques Associated to This Collection ... Process Discovery T1057
It also logs keystrokes, targets Coinomi crypto-wallets, and provides thorough fingerprinting of the local system.
Mitre ATT&CK Tactics And Techniques Associated to This Collection ... Virtualization/Sandbox Evasion T1497
Collected information is converted into XML format and transmitted to the C2 Server through SOAP Message. | Redline Stealer uses WCF for C2 communication... the communication protocol was changed to NetTcpBinding(). NetTcpBinding() has a performance advantage... because SOAP messages are binary encoded and delivered.
When users visit fake shareware sites and click to download, they immediately experience multiple redirects that obfuscate the process for detection by search engines, scanners, and victims, and finally deliver them to a malicious site hosting the threat actor’s intended content. | Once the timeout period is over the loader connects to the remote server requesting a jpg file... once the content is reversed by the malicious program, it transforms into a DLL file.
1,472 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as malware previously found preinstalled on some AceMagic machines from the factory.
Mentioned only as another malware family historically associated with the same IP.
Information stealer that collects credentials, financial data, cryptocurrency-related data, system inventory, and can execute commands and transfer files.
A named stealer malware family mentioned as an example search term for marketplace monitoring; no operational details are provided in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.