RedLine Stealer

MITRE ATT&CK: S1240 View on attack.mitre.org

Aliases: RECORDSTEALER, RedLine Stealer

First seen
2020-01-01 00:00:00
Malware type
credential-stealer, spyware
Family
Malware family
Operating systems
windows
Related IoCs
1951 (1481 malicious)
Last IoC activity
2026-09-02 04:12:08
Profile updated
2026-07-07 13:00:40

Targeted industries: financial-services technology-and-telecommunications retail-and-hospitality

Context

RedLine Stealer is an information-stealer malware variant first identified in 2020. RedLine Stealer is a Malware as a Service (MaaS) and was reportedly sold as either a one-time purchase or a monthly subscription service. Information obtained from RedLine Stealer has been known to be sold on the deep and dark web to Initial Access Brokers (IABs), who use or resell the stolen credentials for further intrusions.

Recent IoC activity

1,498 malicious indicators in Maltiverse are attributed to RedLine Stealer (S1240). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample 877ced13ebaf2b0fbe6b9ec4e332251d6e9d65d7ace653da77003ef4ef0003fe 2026-09-03 2
IP address 3.64.4.198 2026-09-03 4
hostname jixtarelar.xyz 2026-09-03 2
file sample PO#4502968189 Packinglist for confirmation.ex.exe 2026-09-03 1
IP address 3.141.210.37 2026-09-03 6
hostname 2.tcp.ngrok.io 2026-09-03 2
IP address 3.127.181.115 2026-09-03 4
IP address 3.125.188.168 2026-09-03 4
IP address 145.239.200.147 2026-09-03 4
IP address 3.126.224.214 2026-09-03 4
file sample IMG_461349.exe 2026-09-03 1
file sample 862ff11452de99418139941018e044e7802fad311d21ddd396a5476adbe56352 2026-09-03 2
file sample 8638581592e1368094aee96942006f6ed6161f58ed18b3492450c7c21dea133d 2026-09-03 2
file sample 86b2b298949aa8152e801baa096952105a2147fd5a13308f9f27959ffdc2cc2d 2026-09-03 2
hostname 4life.longmusic.com 2026-09-03 1
hostname 2.tcp.eu.ngrok.io 2026-09-03 2
hostname elew3le3lanle.freeddns.org 2026-09-03 2
hostname memoriesweb.tilda.ws 2026-09-03 1
file sample 850edcc529317cac5afbdb048586a9ae1bd69b499e5aeb67d6268a6286c492fd 2026-09-02 3
hostname redline957.duckdns.org 2026-09-02 1

Detection coverage

  • 3 YARA rules
  • 576 Sigma rules

Malware & tools used

  • Code Signing (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Query Registry (attack-pattern)
  • Screen Capture (attack-pattern)
  • Malicious File (attack-pattern)
  • Financial Theft (attack-pattern)
  • Local Account (attack-pattern)
  • Masquerading (attack-pattern)
  • Software Packing (attack-pattern)
  • System Location Discovery (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • System Language Discovery (attack-pattern)
  • Web Service (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Lua (attack-pattern)
  • Data from Local System (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Steal Web Session Cookie (attack-pattern)
  • Browser Information Discovery (attack-pattern)
  • Credentials from Password Stores (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)

Exploited vulnerabilities

  • CVE-2017-11882 (vulnerability)

Detection rules

  • ARKBIRD_SOLG_Mal_Stealer_NET_Redline_Aug_2020_1 (yara-rule)
  • SECUINFRA_MAL_Redline_Certificate_Bosch (yara-rule)
  • SECUINFRA_MAL_Redline_Certificate_Geforce (yara-rule)

Reports & references

  • Microsoft — Dev 0537 Criminal Actor Targeting Organizations For Data Exfiltration And Destruction (report)
  • krebsonsecurity.com — Fbi Hacker Dropped Stolen Airbus Data On 9 11 (report)
  • cloud.google.com — Unc5537 Snowflake Data Theft Extortion (report)
  • research.checkpoint.com — Stargazers Ghost Network (report)
  • Palo Alto Unit 42 — Lapsus Group (report)
  • medium.com — Inside View Of Brazzzersff Infrastructure 89B9188Fd145 (report)
  • intel471.com — Privateloader Malware (report)
  • go.recordedfuture.com — Cta 2022 0802 (report)
  • Palo Alto Unit 42 — Bluesky Ransomware (report)
  • blogs.blackberry.com — Dot Net Stubs Sowing The Seeds Of Discord (report)
  • spamhaus.org — Botnet Threat Update January To June 2025 (report)
  • info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — Jan Jun%202024%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2022%20Q3%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q3%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — Q4%202023%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q1%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q2%20Botnet%20Threat%20Update (report)
  • blog.sekoia.io — Exposing Fakebat Loader Distribution Methods And Adversary Infrastructure (report)
  • spamhaus.org — 2020 Q2 Spamhaus Botnet Threat Report (report)
  • proofpoint.com — Ta569 Socgholish And Beyond (report)
  • fourcore.io — Threat Hunting Browser Credential Stealing (report)
  • ciphertechsolutions.com — Roboski Global Recovery Automation (report)
  • securityintelligence.com — Roboski Global Recovery Automation (report)
  • blog.netlab.360.com — Purecrypter (report)

External references