RedLine Stealer
MITRE ATT&CK: S1240 View on attack.mitre.org
Aliases: RECORDSTEALER, RedLine Stealer
- First seen
- 2020-01-01 00:00:00
- Malware type
- credential-stealer, spyware
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 1951 (1481 malicious)
- Last IoC activity
- 2026-09-02 04:12:08
- Profile updated
- 2026-07-07 13:00:40
Targeted industries: financial-services technology-and-telecommunications retail-and-hospitality
Context
RedLine Stealer is an information-stealer malware variant first identified in 2020. RedLine Stealer is a Malware as a Service (MaaS) and was reportedly sold as either a one-time purchase or a monthly subscription service. Information obtained from RedLine Stealer has been known to be sold on the deep and dark web to Initial Access Brokers (IABs), who use or resell the stolen credentials for further intrusions.
Recent IoC activity
1,498 malicious indicators in Maltiverse are attributed to RedLine Stealer (S1240). The 20 most recently updated:
Detection coverage
- 3 YARA rules
- 576 Sigma rules
Malware & tools used
- Code Signing (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Security Software Discovery (attack-pattern)
- Query Registry (attack-pattern)
- Screen Capture (attack-pattern)
- Malicious File (attack-pattern)
- Financial Theft (attack-pattern)
- Local Account (attack-pattern)
- Masquerading (attack-pattern)
- Software Packing (attack-pattern)
- System Location Discovery (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- System Language Discovery (attack-pattern)
- Web Service (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Lua (attack-pattern)
- Data from Local System (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Standard Encoding (attack-pattern)
- Steal Web Session Cookie (attack-pattern)
- Browser Information Discovery (attack-pattern)
- Credentials from Password Stores (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
Exploited vulnerabilities
- CVE-2017-11882 (vulnerability)
Detection rules
- ARKBIRD_SOLG_Mal_Stealer_NET_Redline_Aug_2020_1 (yara-rule)
- SECUINFRA_MAL_Redline_Certificate_Bosch (yara-rule)
- SECUINFRA_MAL_Redline_Certificate_Geforce (yara-rule)
Reports & references
- Microsoft — Dev 0537 Criminal Actor Targeting Organizations For Data Exfiltration And Destruction (report)
- krebsonsecurity.com — Fbi Hacker Dropped Stolen Airbus Data On 9 11 (report)
- cloud.google.com — Unc5537 Snowflake Data Theft Extortion (report)
- research.checkpoint.com — Stargazers Ghost Network (report)
- Palo Alto Unit 42 — Lapsus Group (report)
- medium.com — Inside View Of Brazzzersff Infrastructure 89B9188Fd145 (report)
- intel471.com — Privateloader Malware (report)
- go.recordedfuture.com — Cta 2022 0802 (report)
- Palo Alto Unit 42 — Bluesky Ransomware (report)
- blogs.blackberry.com — Dot Net Stubs Sowing The Seeds Of Discord (report)
- spamhaus.org — Botnet Threat Update January To June 2025 (report)
- info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — Jan Jun%202024%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2022%20Q3%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q3%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — Q4%202023%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q1%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q2%20Botnet%20Threat%20Update (report)
- blog.sekoia.io — Exposing Fakebat Loader Distribution Methods And Adversary Infrastructure (report)
- spamhaus.org — 2020 Q2 Spamhaus Botnet Threat Report (report)
- proofpoint.com — Ta569 Socgholish And Beyond (report)
- fourcore.io — Threat Hunting Browser Credential Stealing (report)
- ciphertechsolutions.com — Roboski Global Recovery Automation (report)
- securityintelligence.com — Roboski Global Recovery Automation (report)
- blog.netlab.360.com — Purecrypter (report)
External references
- mitre-attack — S1240
- ESET RedLine Stealer November 2024
- Kroll RedLine Stealer August 2024
- Proofpoint RedLine Stealer March 2020
- Splunk RedLine Stealer June 2023
- Veriti RedLine Stealer MAAS April 2023
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy