META is a Windows information-stealing malware family closely associated with RedLine and widely described as a derivative or clone marketed as an improved alternative. It emerged in the broader infostealer ecosystem as a malware-as-a-service offering and gained traction among cybercriminals before being disrupted in October 2024 during Operation Magnus, a multinational law-enforcement action that targeted RedLine and META infrastructure. Prior to that disruption, RedLine and META were assessed to account for a dominant share of infostealer infections and stolen credentials in 2024.
META is designed to harvest sensitive data from infected systems, including browser-stored passwords and cryptocurrency wallet data. Reporting also indicates it can bypass Chromium App-Bound Encryption protections, placing it among a set of modern stealers that adapted to newer browser defenses. Its operators marketed it through criminal channels and bot marketplaces, including positioning it as a successor to or enhancement of RedLine.
Observed delivery has included malspam campaigns using social-engineering lures such as financial-transfer themes and DocuSign-branded macro-enabled spreadsheet attachments. When a victim enables malicious content, the infection chain uses script-based staging to retrieve multiple payload components, apply obfuscation techniques such as Base64 encoding and byte reversal, assemble the final stealer on the host, and establish persistence so the malware survives reboot. META has also been observed using PowerShell to weaken host defenses by modifying Microsoft Defender exclusions.
META primarily targets Windows endpoints used by consumers and enterprise users for credential theft and follow-on criminal exploitation. Stolen data from META infections has been monetized through underground log markets and can support account takeover, fraud, and broader intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
One thing to note is that META modifies Windows Defender via PowerShell to exclude .exe files from scanning, to protect its files from detection.
If the scanning and authentication are successful, command execution occurs to install “mysql,” an XMRig CoinMiner, on the Attack Target server.
If the scanning and authentication are successful, command execution occurs to install “mysql,” an XMRig CoinMiner, on the Attack Target server.
“When executed, RedLine would steal data, including access devices, from victims’ computers.” Infostealers thieve billions of user credentials such as passwords annually.
Scanning and login attempts targeting SSH service honeypots occurred from multiple attack sources.
provided criminals access to “bots” or “browser fingerprints” ... including IP addresses, session cookies, operating system information, and plugins
A clear and persistent sign of the infection is the EXE file generating traffic to a command and control server at 193.106.191[.]162, even after the system reboots, restarting the infection process on the compromised machine.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as infostealer infrastructure dismantled during Operation Magnus in October 2024; mentioned as background in a broader discussion of infostealers.
Go-based propagation malware that scans SSH services using supplied ranges and credentials, executes commands on successful login, installs XMRig, and reports results via HTTP POST.
A RedLine clone mentioned as part of the broader infostealer ecosystem and takedown context.
An infostealer malware family derived from RedLine, mentioned as a target of Operation Magnus.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.