Alexandre Cote Cyr. (2024, November 8). Life on a crooked RedLine: Analyzing the infamous infostealer’s backend. Retrieved September 17, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareRedLine Stealer | RedLine Stealer has collected data stored locally including chat logs and files associated with chat services such as Steam, Discord, and Telegram. |
| T1027.002 Software Packing |
MalwareRedLine Stealer | RedLine Stealer has used obfuscation tools such as DNGuard and Boxed App to pack their code. |
| T1071.001 Web Protocols |
MalwareRedLine Stealer | RedLine Stealer has utilized HTTP for C2 communications. RedLine Stealer has also conducted C2 communications to hardcoded C2 servers over HTTPS. RedLine Stealer has leveraged SOAP protocol for C2 communications. |
| T1204.002 Malicious File |
MalwareRedLine Stealer | RedLine Stealer malware has been executed through the download of malicious files. RedLine Stealer has also lured users to install malware with an Install Wizard interface. |
| T1480 Execution Guardrails |
MalwareRedLine Stealer | RedLine Stealer has built in settings to not operate based on geolocation or country of the victim host. |
| T1539 Steal Web Session Cookie |
MalwareRedLine Stealer | RedLine Stealer has stolen browser cookies and settings. |
| T1553.002 Code Signing |
MalwareRedLine Stealer | RedLine Stealer has used both valid certificates and self-signed digital certificates to appear legitimate. |
| T1555.003 Credentials from Web Browsers |
MalwareRedLine Stealer | RedLine Stealer was designed to steal sensitive information from web browsers, including credit card details, saved credentials, and autocomplete data. RedLine Stealer can also gather credentials from several browsers. |
| T1614 System Location Discovery |
MalwareRedLine Stealer | RedLine Stealer has gathered detailed information about victims’ systems, such as IP addresses, and geolocation. RedLine Stealer has also checked the IP from where it was being executed and leveraged an opensource geolocation IP-lookup service. |
| T1657 Financial Theft |
MalwareRedLine Stealer | RedLine Stealer has collected data from cryptocurrency wallets and harvested credit cards details from browsers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.