Infostealer
RedLine Stealer
Infostealer
23 detections found
Also known as: RedLine, RedLine InfoStealer, RedLine Info Stealer
RedLine Stealer is a Windows information-stealing malware, active since 2020, sold as malware-as-a-service via one-time purchases or monthly subscriptions on underground forums. It harvests credentials, cookies, and autofill data from browsers, plus cryptocurrency wallet and messaging-app data, which is frequently resold to initial access brokers. On October 28, 2024, an international operation (Operation Magnus, DOJ, Dutch National Police, and partners in the UK, Belgium, Portugal, and Australia) seized RedLine's and its sibling META's backend infrastructure and source code, and the U.S. charged alleged developer/administrator Maxim Rudometov; despite this, RedLine and its offshoots continue to see some residual activity.
Detection & eradication references
Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.
- RedLine Stealer, Software S1240 — MITRE ATT&CK
- Dutch Police Disrupt Major Info Stealers RedLine and MetaStealer in Operation Magnus — The Hacker News
- RedLine and META Takedown: A Turning Point in the Infostealer Landscape? — Flashpoint