ATT&CKReferencesProofpoint RedLine Stealer March 2020

Proofpoint RedLine Stealer March 2020

Proofpoint Threat Insight Team, Jeremy H, Axel F. (2020, March 16). New Redline Password Stealer Malware. Retrieved September 17, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
MalwareRedLine Stealer

RedLine Stealer has obtained the username from the victim’s machine.

T1041
Exfiltration Over C2 Channel
MalwareRedLine Stealer

RedLine Stealer has sent victim data to its C2 server or RedLine panel server.

T1071.001
Web Protocols
MalwareRedLine Stealer

RedLine Stealer has utilized HTTP for C2 communications. RedLine Stealer has also conducted C2 communications to hardcoded C2 servers over HTTPS. RedLine Stealer has leveraged SOAP protocol for C2 communications.

T1082
System Information Discovery
MalwareRedLine Stealer

RedLine Stealer can collect information about the local system.

T1087.001
Local Account
MalwareRedLine Stealer

RedLine Stealer has collected account information from the victim’s machine.

T1102
Web Service
MalwareRedLine Stealer

RedLine Stealer has leveraged legitimate file sharing web services to host malicious payloads.

T1480
Execution Guardrails
MalwareRedLine Stealer

RedLine Stealer has built in settings to not operate based on geolocation or country of the victim host.

T1539
Steal Web Session Cookie
MalwareRedLine Stealer

RedLine Stealer has stolen browser cookies and settings.

T1555
Credentials from Password Stores
MalwareRedLine Stealer

RedLine Stealer has obtained credentials from VPN services, FTP clients and Instant Messenger (IM)/Chat clients.

T1555.003
Credentials from Web Browsers
MalwareRedLine Stealer

RedLine Stealer was designed to steal sensitive information from web browsers, including credit card details, saved credentials, and autocomplete data. RedLine Stealer can also gather credentials from several browsers.

T1614
System Location Discovery
MalwareRedLine Stealer

RedLine Stealer has gathered detailed information about victims’ systems, such as IP addresses, and geolocation. RedLine Stealer has also checked the IP from where it was being executed and leveraged an opensource geolocation IP-lookup service.

T1657
Financial Theft
MalwareRedLine Stealer

RedLine Stealer has collected data from cryptocurrency wallets and harvested credit cards details from browsers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.