META is a Windows information-stealing malware family derived from RedLine and marketed to cybercriminals as an improved version of that stealer. It is sold through subscription and lifetime-access offerings and steals passwords stored in Google Chrome, Microsoft Edge, and Mozilla Firefox, along with cryptocurrency wallet data. Stolen information has been traded through underground marketplaces, including TwoEasy.
Observed distribution campaigns use malicious spam emails with fraudulent fund-transfer claims and macro-enabled Excel attachments. DocuSign-themed spreadsheets persuade recipients to enable content, triggering malicious Visual Basic scripts that download additional components and assemble the final payload. Delivery chains use Base64 encoding and reversed-byte payloads to hinder detection. META establishes persistence through the Windows Registry and uses PowerShell to modify Microsoft Defender exclusions so executable files are not scanned. It communicates with command-and-control infrastructure and resumes execution after reboot. META has also demonstrated the ability to bypass Chromium App-Bound Encryption.
In October 2024, the multinational Operation Magnus disrupted infrastructure supporting META and RedLine, including servers, domains, and administrator Telegram accounts. META is distinct from an unrelated Go-based Linux SSH propagation tool also called meta.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
One thing to note is that META modifies Windows Defender via PowerShell to exclude .exe files from scanning, to protect its files from detection.
If the scanning and authentication are successful, command execution occurs to install “mysql,” an XMRig CoinMiner, on the Attack Target server.
If the scanning and authentication are successful, command execution occurs to install “mysql,” an XMRig CoinMiner, on the Attack Target server.
The analysis draws on approximately 44 million infostealer logs and recommends monitoring for "credential exposure," "credential theft," and compromised data following law-enforcement takedowns.
“When executed, RedLine would steal data, including access devices, from victims’ computers.” Infostealers thieve billions of user credentials such as passwords annually.
Scanning and login attempts targeting SSH service honeypots occurred from multiple attack sources.
provided criminals access to “bots” or “browser fingerprints” ... including IP addresses, session cookies, operating system information, and plugins
A clear and persistent sign of the infection is the EXE file generating traffic to a command and control server at 193.106.191[.]162, even after the system reboots, restarting the infection process on the compromised machine.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer named as a target of Operation Magnus. The content provides no further technical or operational detail.
Named as infostealer infrastructure dismantled during Operation Magnus in October 2024; mentioned as background in a broader discussion of infostealers.
Go-based propagation malware that scans SSH services using supplied ranges and credentials, executes commands on successful login, installs XMRig, and reports results via HTTP POST.
A RedLine clone mentioned as part of the broader infostealer ecosystem and takedown context.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.