RedLine Stealer is malicious software that steals sensitive data from browsers, apps, and crypto wallets. This malware collects device information and can launch ransomware attacks.
Operating as a remote access trojan, it exfiltrates data to hackers who sell it on dark web forums. Available as malware-as-a-service (MaaS), its affordability and effectiveness make it a widely used threat.
Emerging in March 2020, RedLine Stealer spread through a deceptive email campaign that masqueraded as a COVID-19 research company, tricking users into downloading malicious calculation software.
Full Name: Redline
First Appearance: March 2020
Related Actor: Glade (The actor who posted the original Redline thread)
MaaS Subscription
Since the original market bot is down at the moment of writing this paragraph, this information can only be based on the information discussed by other users on the dark web.
One month subscription – 150$
Lifetime subscription – 900$
Redline – Stealer Evolution
Redline first appeared on the popular Russian DW form Exploit in February 2020 by an actor named Glade. The actor offers a simple-to-use Telegram bot which offers the subscription packages and joins you into a private chat for support once the payment has been made.

Redline’s first appearance, 19/02/2020
The stealer started gaining popularity and by 2021 became one of the most common stealers in threat reports. The developers also implemented high configurability, allowing users to target specific file extensions and folders. They also extended their distribution methods beyond just phishing emails, including malicious Trojans, Youtube and Google ads, and SEO.
Redline became so popular that it was used as a base for other stealers, as well as “cracked” versions of the builds. Even with several strong players entering the infostealer scene in 2022 like Lumma and StealC, Redline still stayed prominent.
Redline Takedown – Oct 28th, 2024
On october 28th, 2024, Dutch National Police along with the FBI and several other organizations disrupted the operation of the Redline and Meta infostealers in an operation now known as Operation Magnus.

https://www.operation-magnus.com/
The operation was on a huge scale, included teams from various security agencies from all over the world. The team even had their own Telegram for users to anonymously report information (t.me/OperationMagnus)
Obviously, conversation on the dark web was tense. Many users showed concerns and panic regarding the situation

Redline – Technical Capabilities
Programming Language: C#
Build Weight: 100-250KB
Data Types Stolen
Operating Systems Targeted: all modern Windows version since Windows 7
CPU Targeted: x84, x64
Extensions:
- MetaMask 2) Binance Chain Wallet 3) Coinbase Wallet 4) TronLink 5) Ronin Wallet 6) Nifty Wallet 7) Math Wallet 8) Atomic Wallet 9) Yoroi 10) Exodus
Cold wallets:
- Bitcoin 2) Litecoin 3) 42Coin 4) Atomic 5) Alphacoin 6) Americancoin 7) AndroidsTokens 8) Anoncoin 9) Argentum 10) AsicCoin 11) avingCoin 12) BBQCoin 13) BeaoCoin 14) BitBar 15) bitgem 16) bits 17) Blakecoin 18) Bottlecaps 19) BountyCoin 20) Bytecoin 21) CasinoCoin 22) CHNCoin 23) Cloudcoin 24) Coinomi 25) Colossuscoin 26) Copper Bars 27) CosmosCoin 28) CPU2coin 29) Craftcoin 30) Crimecoin 31) CryptogenicBullion 32) CryptogenicBullionC 33) Devcoin 34) Diamond 35) DigitalCoin 36) Dogecoin 37) DollarPounds 38) Dragoncoin 39) EagleCoin 40) Earthcoin 41) ElephantCoin 42) Electrum 43) Exodus 44) Ethereum 45) Extremecoin 46) EzCoin 47) Fastcoin 48) FeatherCoin 49) FerretCoin 50) Florincoin 51) Franko 52) FrankoCoin 53) FreeCoin 54) Freicoin 55) Galaxycoin 56) Gamecoin 57) Guarda 58) GlobalCoin 59) Goldcoin 60) Grain 61) GrandCoin 62) Growthcoin 63) HoboNickels 64) infinitecoin 65) ItalyCoin 66) Ixcoin 67) Joulecoin 68) Jaxx 69) Jupitercoin 70) KingCoin 71) krugercoin 72) last Coin 73) Lebowskis 74) Liquidcoin 75) Lucky7Coin 76) LuckyCoin 77) Maples 78) mastercoin 79) MasterCoin 80) Mavro 81) Megacoin 82) MEMEcoin 83) MemoryCoin 84) Monero 85) Mincoin 86) NaanaYaM 87) Namecoin 88) NanoTokens 89) Neocoin 90) NetCoin 91) NovaCoin 92) Nuggets 93) NXTCoin 94) Onecoin 95) OpenSourcecoin 96) Orbitcoin 97) Paycoin 98) PEERCoin 99) Pennies 100) PeopleCoin 101) PhenixCoin 102) Philosopherstone 103) PlayToken 104) PPcoin 105) PrimeCoin 106) ProtoShares 107) ProtoSharesCoin 108) QuarkCoin 109) RealCoin 110) Redcoin 111) RichCoin 112) RoyalCoin 113) Sauron Rings 114) Secondscoin 115) SecureCoin 116) Sexcoin 117) SHITcoin 118) Sifcoin 119) Skycoin 120) Spots 121) supercoin 122) TagCoin 123) TEKcoin 124) Terracoin 125) TicketsCoin 126) tumcoin 127) UnitedScryptCoin 128) Unobtanium 129) UScoin 130) ValueCoin 131) Worldcoin 132) Waves 133) XenCoin 134) YACoin 135) Ybcoin 136) ZcCoin 137) ZenithCoin 138) Zetacoin.
Browsers:
- Chrome 2) Edge 3) Brave 4) Vivaldi 5) Opera 6) Yandex 7) Comodo Dragon 8) SRWare Iron 9) Torch 10) Chromium
Applications:
- Telegram 2) Discord 3) Skype 4) Steam 5) FileZilla 5) WinSCP 6) NordVPN 7) OpenVPN 8) ProtonVPN
2FA Extensions
Files: grabs .txt, .doc, .docx, .xls, .xlsx, .pdf, .key, .pem, .p12, .wallet, .ldb, .log files from typical directories: desktop, documents, downloads, appdata (lacal/roaming), programdata.
Command & Control Server
Once the user buys the stealer, he gets simple instructions on how to download and operate the C2 panel. It is also very easy to navigate and contains the following sections:
Logs: display information about the infected hosts such as HWID, IP Addresses, build ID of the stealer used and countries and number of captured credentials.
Statistic panel: displays the amount of stolen information on hosts, the top 10 OS (Operating Systems), antiviruses, and countries.
Advertisement panel: shows the links to third-party service providers.
Log Sorter – the feature allows the attacker to sort the logs by the country, BuildID, OS, cookies, and passwords by the domain. The attacker can specify what type of logs will be saved to the machine
Loader Tasks: contains interesting features allowing an attacker to load additional payloads to the infected machine like enter a specific website or execute a specific command.
Guest Links: used for users who spread the stealers via installers or advertisers. We believe that this link is used to build up a statistical panel of the users who visited the malicious landing page that hosts the payload.
Wallet Checker: allows an attacker to check for the cryptocurrency balance of the stolen crypto wallet.
Telegram: in the Telegram section, an attacker can specify their Telegram Bot that is used to receive the logs and notify the attacker on the successful infection by sending the specified logs
Builder: one of the crucial parts of the panel. This is where the attacker specifies the IPs of their servers, the Build ID, generates the stealer payload, signs the file, and obfuscates it if needed. The attacker can also specify the fake error message for the victims when they open the executable. “Send log by parts” allows the attacker to receive the stolen logs in parts, so if the antivirus (AV) flags the stealer during the runtime or right before the launch, the stealer will send everything it was able to collect on the host before the AV jumps in.
Black Lists: the attacker can specify the countries, IPs an HWIDs, build IDs from where the stealer will not exfiltrate data from. It’s worth mentioning that all countries in the Commonwealth of Independent States (CIS) are blacklisted automatically, and instead, attackers who aim to receive the stolen logs from CIS countries usually switch to MetaStealer as the anti-CIS is not applicable for this MetaStealer.
Settings: contains the functionality of the stealer specified by an attacker – the data that needs to be exfiltrated and what folders and domains to search for.
Redline – TTPs
Attack Vector
Since Redline was a very prominent, long lasting infostealer, it evolved through the years, showing different variations of delivery and installation.

Another known infection chain (https://medium.com/@idan_malihi/redline-stealer-malware-analysis-76506ef723ab)
Delivery
There were many known delivery methods to Redline. Some include Phishing Emails during COVID-19, fake or infected app downloads like Netflix, or infected projects on GitHub.
One interesting technique seen used is “infect a friend.” Once downloading a fake project from GitHub, the malware encourages you to share it with a friend to “unlock the full version,” possibly infecting the colleague’s computer as well.

Installation
Once the malware is installed, Redline uses an obfuscator to make the code unreadable and harder to process, while on the malware side the commands stay simple and exposed.
Information Gathering
Communication with the C2 is done over HTTP, in XML and through SOAP messages (a protocol that is used for structuring messages in web services and facilitating communication between different applications or systems over the internet).
The communication with the C2 is done in a IFF style – the infected computer sends a 32bit message to the C2 server and only when it recieves the correct answer it will send over the infected information or perform any requested action.
The malware starts with browsers. Redline steals the browser’s version information, account credentials, auto-fill data, cookies, credit cards, login data, and geolocation from Chrome and Opera browsers.
The malware then searches for relevant crypto wallets on the computer.
Finally, it gathers all of the information regarding the system including IP, country, HWID, and more.
The stealer stores this information in a ready-to-send file and proceeds to look for documents and software information. It can send the file when complete or in chunks, depending on the actor’s settings.
MITRE ATT&CK
Malware ID: no official MITRE page
| Tactic | Technique ID | Technique Name |
|---|---|---|
| Persistence | Scheduled Task | T1053 |
| Defense Evasion | Deobfuscate/Decode Files or Information | T1140 |
| Defense Evasion | Masquerading | T1036 |
| Defense Evasion | Process Injection | T1055 |
| Credential Access | OS Credential Dumping | T1003 |
| Discovery | File and Directory Discovery | T1083 |
| Discovery | Process Discovery | T1057 |
| Discovery | Query Registry | T1012 |
| Discovery | System Information Discovery | T1082 |
| Collection | Data from Local System | T1005 |
| Command and Control | Application Layer Protocol | T1071 |
| Command and Control | Non-Application Layer Protocol | T1095 |
| Command and Control | Web Service | T1102 |
Redline – Log Structure

- File name – XX(country)[HWID] [YYYY-MM-DDT HH_MM_SS.XXXX](time of log, not publication)
This file naming system does not seem to appear in logs prior to May. Logs from April checked by chance show file name not divided by [].
- Possible Documents: not all documents are present in every log. For a more streamlined reading experience, the files here are detailed in alphabetical order.
- Autofills: divided by operating system (Chrome, Edge, etc.) in the following format:
Name: ______
Value: ______
===============
- Cookies: divided by operating system (Chrome, Edge, etc.). Raw cookie format.
- Credit Cards: credit card information, divided by browser in the following format
CN/card:
Date/expired:
Name/holder:
Target:
- Discord: discord data
- Domain Detects: mentions PDD and CDD, unsure what that stands for. Mostly displaying NOT FOUND but occasionally a link.
- FileGrabber: physical documents (Word, Notepad, etc.)
- ImportantAutofills: special important autofills (name, mail, pincode, etc.)
- InstalledBrowsers: List of downloaded softwares + versions. Occasionally comes up empty.
- Installed Software: numerical list of installed software
- Passwords: list of passwords in the following format
URL: (site link)
Username:
Password:
Application: (used application/browser)
===============
- ProcessList: full dashes, occasional ID, name, and command
- Steam: Steam data
- Telegram: Telegram information files.
- UserInformation: important metadata about the user. Uses the following format. Occasionally it will also have more fields such as Username or Build.
- Additional files: some logs include additional files named by a series of seemingly random characters (KNPIBf, Luwi1x, ) the files themselves only include the Redline logo.
July Leaks:
- Format change:
- Passwords: dashes between passwords removed.
- processList: no dashes, only list of commands.
- UserInformation: format change
- Possible additional files: there are files that were not present in the September logs checked. There were no files in the September logs that did not appear in July.
- Clipboard: what is copied on the device
- Mnemonics: seems to be file locations and wording
- Restore: tokens divided by browser
- UserAgents: divided by browser