RedLine Stealer is a Windows information-stealing malware family written in C# that emerged in early 2020 and became one of the most widely used commodity stealers in the cybercrime ecosystem. It is commonly sold and distributed through malware-as-a-service and affiliate-style channels, and has been repeatedly observed in broader criminal operations involving credential theft, account compromise, and resale of stealer logs for follow-on intrusion activity.
RedLine primarily targets browser-stored data and other user secrets. Reported capabilities include theft of saved credentials, browser cookies, autofill data, and cryptocurrency wallet information. Its stolen output is frequently packaged into stealer logs that can be traded on underground markets and later used by initial access brokers and other threat actors to compromise enterprise SaaS, cloud, and VPN accounts. RedLine-harvested credentials and session material have been linked to downstream breaches of corporate services including cloud file-sharing platforms.
The malware is associated with a broad range of delivery chains rather than a single infection vector. It has been observed delivered by loaders, drive-by download activity, phishing and spearphishing campaigns, fake CAPTCHA or ClickFix-style lures, trojanized or cracked software, fake updates, malvertising, and other social-engineering-heavy distribution methods common to commodity stealers. It also appears in bundled crimeware ecosystems alongside families such as Lumma, Vidar, StealC, Amadey, SmokeLoader, Remcos, and others.
Operationally, RedLine has been tied to command-and-control patterns including SOAP-based communications, and sandboxed samples have shown host discovery behavior such as process enumeration, system information collection, registry queries, storage-device enumeration, delayed execution, and suspicious memory-writing or injection-related activity. Beyond direct theft, RedLine has also been used as an enabling component in larger campaigns, including targeted phishing and business-email-compromise-style operations, and has been leveraged to support secondary malware deployment.
RedLine has had substantial criminal market presence for several years and was a leading stealer family across log marketplaces before later competition from newer families. Law-enforcement disruption in 2024 targeted backend infrastructure associated with RedLine, but older builds and repackaged variants have continued to appear in subsequent incidents. The malware remains significant because its output is routinely weaponized for credential-based intrusions, cloud account compromise, and financially motivated cybercrime.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ClearSky Cyber Security has uncovered a new zero-day vulnerability, CVE-2024-43451, actively exploited in the wild, targeting Windows systems primarily in Ukraine. This flaw enables attackers to exploit URL files for malicious activity by performing actions as simple as a single right-click.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The RedLine Stealer Trojan is used to spread a malware called Bobik.
LAPSUS$ acquired and used the Redline password stealer in their operations.
Amadey is a modular Windows botnet sold as MaaS by author "InCrease" on XSS/Exploit forums, active since 2018. It commonly drops Lumma, StealC, RedLine, CoinMiners, and RATs.
ClearSky researchers observed that this vulnerability has been used to distribute various malware, including Redline Stealer and SparkRAT.
Others include StealC, RedLine, Odebug and other Phemedrone variants, and NodeJS loaders and downloaders.
Hudson Rock researchers investigated the alleged breaches and found the threat actor relied on distributing infostealers such as RedLine, Lumma, or Vidar... to harvest credentials.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Rather than breaking into networks, modern threat actors buy their way in by purchasing “stealer logs” containing valid usernames, passwords, session cookies, and SSO tokens harvested from infected endpoints, then replaying those sessions directly against cloud consoles, SaaS platforms, and VPN gateways.
Operators distribute malware through pirated software repositories, malvertising networks, and compromised websites with the goal of infecting as many machines as possible.
Rather than breaking into networks, modern threat actors buy their way in by purchasing “stealer logs” containing valid usernames, passwords, session cookies, and SSO tokens harvested from infected endpoints, then replaying those sessions directly against cloud consoles, SaaS platforms, and VPN gateways.
Suspicious use of WriteProcessMemory ... PID 2680 wrote to memory of 1712 ... PID 3316 wrote to memory of 3832
Rather than breaking into networks, modern threat actors buy their way in by purchasing “stealer logs” containing valid usernames, passwords, session cookies, and SSO tokens harvested from infected endpoints, then replaying those sessions directly against cloud consoles, SaaS platforms, and VPN gateways.
Suspicious use of WriteProcessMemory ... PID 2680 wrote to memory of 1712 ... PID 3316 wrote to memory of 3832
Rather than breaking into networks, modern threat actors buy their way in by purchasing “stealer logs” containing valid usernames, passwords, session cookies, and SSO tokens harvested from infected endpoints, then replaying those sessions directly against cloud consoles, SaaS platforms, and VPN gateways.
When successfully deployed and executed, information-stealing malware can harvest credentials (usernames, passwords, and session cookies) from infected environments and export them as logs to the attackers’ server.
Related techniques include T1056 (Input Capture/keylogging) and T1557 (session/token interception), both observed across current stealer families.
They extract: Browser-saved credentials, autofill data Active session cookies (which bypass MFA entirely) Authentication tokens for GitHub, GitLab, AWS, Azure, and GCP
MITRE ATT&CK maps this behavior primarily to Credential Access (TA0006), specifically T1555 – Credentials from Password Stores and its sub-technique T1555.003 – Credentials from Web Browsers, covering theft of saved browser passwords, cookies, and autofill data.
MITRE ATT&CK maps this behavior primarily to Credential Access (TA0006), specifically T1555 – Credentials from Password Stores and its sub-technique T1555.003 – Credentials from Web Browsers, covering theft of saved browser passwords, cookies, and autofill data.
Checks computer location settings ... Looks up country code configured in the registry, likely geofence. Query Registry T1012
Related techniques include T1056 (Input Capture/keylogging) and T1557 (session/token interception), both observed across current stealer families.
VMRay Labs continued the research with “212.193.30[.]45”, which behaves not as a console but as a proxy/redirector that fronts the actor’s infrastructure behind the GitHub domain.
The SOAPAction header pointing at tempuri.org is consistent with RedLine’s SOAP-based communication which confirms the family.
310 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer and early pioneer of the malware-as-a-service stealer model. The content describes it as a legacy but still relevant source of stolen credentials appearing in older logs used for follow-on cloud breaches.
Mentioned as another malware family delivered by the same crypter/tooling ecosystem.
Information stealer referenced as using sanctioned hosting infrastructure.
Infostealer malware whose panels were hosted by Aeza Group according to the article.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.