Info Stealer
RedLine Stealer
First seen: 2020-03 • Status: active
Currently Active Threat
RedLine is a password-stealing program that criminals can rent cheaply online. Once it infects your computer, it grabs all saved passwords from your browser, steals cryptocurrency wallet data, and sends everything to hackers. It spreads through fake software downloads and phishing emails.
Overview
RedLine Stealer is a commodity information-stealing malware sold on Russian-speaking cybercrime forums. It harvests credentials from browsers, cryptocurrency wallets, VPN clients, and other applications. The malware is available as Malware-as-a-Service (MaaS) for approximately $150-200 per month, making it accessible to low-skilled threat actors.
Also Known As
RedLine, RedLine Infostealer
How It Spreads
- • Phishing emails with malicious attachments
- • Fake software cracks and keygens
- • Malicious Google Ads redirecting to fake download sites
- • Compromised legitimate software installers
- • Discord and Telegram malware distribution channels
What It Does
- • Steals saved passwords from Chrome, Firefox, Edge, and other browsers
- • Extracts cryptocurrency wallet data and private keys
- • Harvests VPN credentials (NordVPN, OpenVPN, ProtonVPN)
- • Captures Discord tokens and session cookies
- • Collects system information and installed software list
- • Exfiltrates data via HTTP POST to command-and-control servers
Is your business exposed?
Target Platforms
Windows 7, Windows 10, Windows 11
Detection Tips
- • Monitor for processes accessing browser credential storage locations
- • Alert on unusual HTTP POST traffic to unknown external IPs
- • Watch for processes reading cryptocurrency wallet files
- • Detect execution from temporary or download directories
- • Monitor registry queries for installed VPN software
MITRE ATT&CK Techniques
T1555, T1539, T1552, T1083, T1082
If You're Infected
- 1.
Isolate the infected machine from the network immediately
- 2.
Reset all passwords for accounts accessed from the infected machine
- 3.
Revoke and regenerate all API keys and access tokens
- 4.
Transfer cryptocurrency to new wallets with fresh keys
- 5.
Run full antivirus scan and reimage if necessary
- 6.
Enable MFA on all accounts that support it
Related Malware
Is your business exposed?
Check if your company data is circulating on the dark web
Free scan • No credit card required