MetaStealer

First seen
2022-03-07 00:00:00
Malware type
credential-stealer, spyware
Last IoC activity
2026-07-22 02:19:02
Profile updated
2026-07-07 13:13:46

Targeted industries: financial-services technology-and-telecommunications

Context

On March 7, 2022, KELA observed a threat actor named _META_ announcing the launch of META – a new information-stealing malware, available for sale for USD125 per month or USD1000 for unlimited use. The actor claimed it has the same functionality, code, and panel as the Redline stealer, but with several improvements.

Detection coverage

  • 5 YARA rules

Detection rules

  • RUSSIANPANDA_Metastealer_NET_Reactor_Packer (yara-rule)
  • RUSSIANPANDA_Metastealer_Core_Payload (yara-rule)
  • RUSSIANPANDA_Metastealer (yara-rule)
  • DITEKSHEN_MALWARE_Win_Metastealer (yara-rule)
  • MALPEDIA_Win_Metastealer_Auto (yara-rule)

Reports & references

  • cloud.google.com — Unc5537 Snowflake Data Theft Extortion (report)
  • ke-la.com — Information Stealers A New Landscape (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Metastealer (report)
  • accenture.com — Information Stealer Malware On Dark Web (report)
  • research.nccgroup.com — Metastealer Filling The Racoon Void (report)
  • research.openanalysis.net — Metastealer (report)
  • medium.com — Metastealer String Decryption And Dga Overview 5F38F76830Cd (report)
  • russianpanda.com — Metastealer Part 2 (report)
  • g0njxa.medium.com — Approaching Stealers Devs A Brief Interview With Meta 8Ae628Dfab8C (report)
  • defentive.medium.com — The Phantom Threat Inside Unc5518S Invisible Empire Of Metastealer Operations Defentive 3C05359Dcae0 (report)
  • russianpanda.com — Metastealer Redline'S Doppelganger (report)
  • isc.sans.edu — 28522 (report)
  • blog.sekoia.io — Traffers A Deep Dive Into The Information Stealer Ecosystem (report)

External references