MetaStealer is a Windows information stealer first observed in 2022 and marketed as a derivative of RedLine Stealer with additional features. Primarily developed in .NET, it harvests credentials, browser data, authentication cookies, and files from compromised systems. Its distribution includes malicious email attachments, macro-enabled Excel documents, email links leading to malicious OneNote documents, and malicious advertisements impersonating legitimate software. Campaigns have also used gaming and tax-related lures.
MetaStealer employs string and configuration encryption, control-flow and proxy-call obfuscation, and domain generation algorithms for command-and-control discovery. Both an older algorithm and a newer wordlist-based algorithm have been observed. Infection chains have established persistence through Windows logon configuration and retrieved encoded payload components from public hosting services. Analyzed samples have attempted to weaken Microsoft Defender protection by adding executable-file exclusions. MetaStealer has also developed broader post-compromise functionality beyond information theft.
An updated Chrome-cookie theft capability observed in September 2024 bypasses Application-Bound Encryption by impersonating a SYSTEM token and abusing Chrome’s elevation-service COM interface to decrypt the application-bound key. This implementation requires elevated privileges. Stolen authentication cookies enable web-session hijacking. MetaStealer was marketed by an underground actor using the name META and has been used by Sticky Werewolf. Credentials exposed through MetaStealer were among those associated with UNC5537’s compromises of Snowflake customer environments; this does not establish that UNC5537 operated the original malware infections.
A separately documented macOS information-stealer family also uses the name MetaStealer. Observed in 2023, it consists of heavily obfuscated Go-based Intel x86-64 binaries distributed in malicious application bundles through business-themed social engineering, including fake clients and counterfeit application installers. It targets keychain data, saved passwords, and files. Its Intel binaries require Rosetta on Apple silicon. These macOS characteristics should not be conflated with those of the Windows RedLine-derived family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Unit42 recently tweeted about a campaign starting with a malicious email link that downloads a OneNote file used to drop and execute MetaStealer.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
В ĸачестве первоначального веĸтора атаĸ группа использует фишинговые рассылĸи по элеĸтронной почте с вредоносными вложениями... Злоумышленники отправляли вредоносные письма... В качестве приманки Sticky Werewolf использовали поддельное письмо от Минпромторга.
Decrypted Strings: ... Failed to create task definition action = allow program = "
"powershell -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionExtension \"exe\""
File name: open.vbs ... After enabling macro, this VBS file is used to create the persistent EXE | After enabling macro, this VBS file is used to create the persistent EXE
These malicious Excel files are distributed as email attachments. | Traffic generated after enabling Excel macro
Decrypted Strings: ... Failed to create task definition action = allow program = "
REDLINE uses a string obfuscation technique... METASTEALER ... employ[s] obfuscation methods, including obscuring the control flow... STEALC encrypts its strings using a combination of Base64 + RC4.
REDLINE [uses] malicious websites hosting seemingly legitimate applications... METASTEALER [was] encountered ... within a campaign masquerading as Roblox.
METASTEALER requires elevated access because it attempts to impersonate the SYSTEM token during execution; it uses a ContextSwitcher class for token impersonation before decrypting the Chrome key.
Infostealers implement bypasses around Chrome Application-Bound Encryption to retrieve cookie data; STEALC, METASTEALER, PHEMEDRONE, XENOSTEALER, and LUMMA recover cookies in plaintext.
After landing on the C2 routine, instead of decrypting a static list of servers, the sample used a domain generation algorithm[3], (DGA) to derive the list.
After seeing references to backconnect, socks, and loader id’s in the decrypted strings, we can see that the improvements made to this tool now offer more than just credential theft.
128 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named stealer accounting for 995 of the 1,544 malware domains reported under .xyz. Its capabilities and delivery methods are not described.
MetaStealer is described as using a new wordlist-based DGA while older DGA infrastructure remains active. Its gate/proxy servers are domain-agnostic and rely more on IP, port, URI, and HTTP headers for traffic forwarding.
MetaStealer is described as malware using both an older and a new wordlist-based DGA for C2-related domain generation, with gate/proxy servers that are largely agnostic to the domain used and instead rely on IP, port, URI, and HTTP headers.
Referenced only as a comparison family that did not technically match the observed sample.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.