Info Stealer

RedLine Stealer

First seen: 2020-03 • Status: active

Currently Active Threat

RedLine is a password-stealing program that criminals can rent cheaply online. Once it infects your computer, it grabs all saved passwords from your browser, steals cryptocurrency wallet data, and sends everything to hackers. It spreads through fake software downloads and phishing emails.

Overview

RedLine Stealer is a commodity information-stealing malware sold on Russian-speaking cybercrime forums. It harvests credentials from browsers, cryptocurrency wallets, VPN clients, and other applications. The malware is available as Malware-as-a-Service (MaaS) for approximately $150-200 per month, making it accessible to low-skilled threat actors.

Also Known As

RedLine, RedLine Infostealer

How It Spreads

  • Phishing emails with malicious attachments
  • Fake software cracks and keygens
  • Malicious Google Ads redirecting to fake download sites
  • Compromised legitimate software installers
  • Discord and Telegram malware distribution channels

What It Does

  • Steals saved passwords from Chrome, Firefox, Edge, and other browsers
  • Extracts cryptocurrency wallet data and private keys
  • Harvests VPN credentials (NordVPN, OpenVPN, ProtonVPN)
  • Captures Discord tokens and session cookies
  • Collects system information and installed software list
  • Exfiltrates data via HTTP POST to command-and-control servers

Is your business exposed?

Target Platforms

Windows 7, Windows 10, Windows 11

Detection Tips

  • Monitor for processes accessing browser credential storage locations
  • Alert on unusual HTTP POST traffic to unknown external IPs
  • Watch for processes reading cryptocurrency wallet files
  • Detect execution from temporary or download directories
  • Monitor registry queries for installed VPN software

MITRE ATT&CK Techniques

T1555, T1539, T1552, T1083, T1082

If You're Infected

  1. 1.

    Isolate the infected machine from the network immediately

  2. 2.

    Reset all passwords for accounts accessed from the infected machine

  3. 3.

    Revoke and regenerate all API keys and access tokens

  4. 4.

    Transfer cryptocurrency to new wallets with fresh keys

  5. 5.

    Run full antivirus scan and reimage if necessary

    Malwarebytes

  6. 6.

    Enable MFA on all accounts that support it

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required