MetaStealer
- First seen
- 2022-03-07 00:00:00
- Malware type
- credential-stealer, spyware
- Last IoC activity
- 2026-07-22 02:19:02
- Profile updated
- 2026-07-07 13:13:46
Targeted industries: financial-services technology-and-telecommunications
Context
On March 7, 2022, KELA observed a threat actor named _META_ announcing the launch of META – a new information-stealing malware, available for sale for USD125 per month or USD1000 for unlimited use. The actor claimed it has the same functionality, code, and panel as the Redline stealer, but with several improvements.
Detection coverage
- 5 YARA rules
Detection rules
- RUSSIANPANDA_Metastealer_NET_Reactor_Packer (yara-rule)
- RUSSIANPANDA_Metastealer_Core_Payload (yara-rule)
- RUSSIANPANDA_Metastealer (yara-rule)
- DITEKSHEN_MALWARE_Win_Metastealer (yara-rule)
- MALPEDIA_Win_Metastealer_Auto (yara-rule)
Reports & references
- cloud.google.com — Unc5537 Snowflake Data Theft Extortion (report)
- ke-la.com — Information Stealers A New Landscape (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Metastealer (report)
- accenture.com — Information Stealer Malware On Dark Web (report)
- research.nccgroup.com — Metastealer Filling The Racoon Void (report)
- research.openanalysis.net — Metastealer (report)
- medium.com — Metastealer String Decryption And Dga Overview 5F38F76830Cd (report)
- russianpanda.com — Metastealer Part 2 (report)
- g0njxa.medium.com — Approaching Stealers Devs A Brief Interview With Meta 8Ae628Dfab8C (report)
- defentive.medium.com — The Phantom Threat Inside Unc5518S Invisible Empire Of Metastealer Operations Defentive 3C05359Dcae0 (report)
- russianpanda.com — Metastealer Redline'S Doppelganger (report)
- isc.sans.edu — 28522 (report)
- blog.sekoia.io — Traffers A Deep Dive Into The Information Stealer Ecosystem (report)