Splunk Threat Research Team. (2023, June 1). Do Not Cross The 'RedLine' Stealer: Detections and Analysis. Retrieved September 17, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareRedLine Stealer | RedLine Stealer has encrypted and encoded configuration data with Base64 and XOR functions. |
| T1033 System Owner/User Discovery |
MalwareRedLine Stealer | RedLine Stealer has obtained the username from the victim’s machine. |
| T1071.001 Web Protocols |
MalwareRedLine Stealer | RedLine Stealer has utilized HTTP for C2 communications. RedLine Stealer has also conducted C2 communications to hardcoded C2 servers over HTTPS. RedLine Stealer has leveraged SOAP protocol for C2 communications. |
| T1082 System Information Discovery |
MalwareRedLine Stealer | RedLine Stealer can collect information about the local system. |
| T1087.001 Local Account |
MalwareRedLine Stealer | RedLine Stealer has collected account information from the victim’s machine. |
| T1102 Web Service |
MalwareRedLine Stealer | RedLine Stealer has leveraged legitimate file sharing web services to host malicious payloads. |
| T1113 Screen Capture |
MalwareRedLine Stealer | RedLine Stealer can capture screenshots on a compromised host. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRedLine Stealer | RedLine Stealer has decoded its payload prior to execution. |
| T1217 Browser Information Discovery |
MalwareRedLine Stealer | RedLine Stealer can collect information from browsers and browser extensions. |
| T1497 Virtualization/Sandbox Evasion |
MalwareRedLine Stealer | RedLine Stealer has an anti-sandbox technique that requires the malware to consistently check with the C2 server, if the communication fails RedLine Stealer will not continue execution. |
| T1518 Software Discovery |
MalwareRedLine Stealer | RedLine Stealer can get a list of programs on the victim device. |
| T1539 Steal Web Session Cookie |
MalwareRedLine Stealer | RedLine Stealer has stolen browser cookies and settings. |
| T1555 Credentials from Password Stores |
MalwareRedLine Stealer | RedLine Stealer has obtained credentials from VPN services, FTP clients and Instant Messenger (IM)/Chat clients. |
| T1555.003 Credentials from Web Browsers |
MalwareRedLine Stealer | RedLine Stealer was designed to steal sensitive information from web browsers, including credit card details, saved credentials, and autocomplete data. RedLine Stealer can also gather credentials from several browsers. |
| T1614.001 System Language Discovery |
MalwareRedLine Stealer | RedLine Stealer can retrieve system default language and time zone. |
| T1657 Financial Theft |
MalwareRedLine Stealer | RedLine Stealer has collected data from cryptocurrency wallets and harvested credit cards details from browsers. |
| T1685 Disable or Modify Tools |
MalwareRedLine Stealer | RedLine Stealer can disable security software and update services. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.