ATT&CKSoftwareRedLine Stealer

RedLine Stealer

S1240

Malware.View on attack.mitre.org

About this malware

RedLine Stealer is an information-stealer malware variant first identified in 2020. RedLine Stealer is a Malware as a Service (MaaS) and was reportedly sold as either a one-time purchase or a monthly subscription service. Information obtained from RedLine Stealer has been known to be sold on the deep and dark web to Initial Access Brokers (IABs), who use or resell the stolen credentials for further intrusions.

Techniques used35

Procedure examples35

TechniqueProcedure example
T1005
Data from Local System

RedLine Stealer has collected data stored locally including chat logs and files associated with chat services such as Steam, Discord, and Telegram.

T1012
Query Registry

RedLine Stealer can query the Windows Registry.

T1016
System Network Configuration Discovery

RedLine Stealer can enumeate information about victims’ systems including IP addresses.

T1027.002
Software Packing

RedLine Stealer has used obfuscation tools such as DNGuard and Boxed App to pack their code.

T1027.010
Command Obfuscation

RedLine Stealer has obfuscated scripts within text files used in execution.

T1027.013
Encrypted/Encoded File

RedLine Stealer has encrypted and encoded configuration data with Base64 and XOR functions.

T1033
System Owner/User Discovery

RedLine Stealer has obtained the username from the victim’s machine.

T1036
Masquerading

RedLine Stealer malware has masqueraded as legitimate software such as "PDF Converter Software" which has been distributed through poisoned search engine results often resembling legitimate software lures with the combination of typo squatted domains.

T1041
Exfiltration Over C2 Channel

RedLine Stealer has sent victim data to its C2 server or RedLine panel server.

T1053.005
Scheduled Task

RedLine Stealer has achieved persistence via scheduled tasks.

T1059.003
Windows Command Shell

RedLine Stealer has executed windows cmd using `ErrorHandler.cmd` to create scheduled tasks.

T1059.011
Lua

RedLine Stealer malware has leveraged Lua bytecode to perform malicious behavior.

T1071.001
Web Protocols

RedLine Stealer has utilized HTTP for C2 communications. RedLine Stealer has also conducted C2 communications to hardcoded C2 servers over HTTPS. RedLine Stealer has leveraged SOAP protocol for C2 communications.

T1082
System Information Discovery

RedLine Stealer can collect information about the local system.

T1087.001
Local Account

RedLine Stealer has collected account information from the victim’s machine.

View all 35 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References5

  1. ESET RedLine Stealer November 2024 Open source
    Alexandre Cote Cyr. (2024, November 8). Life on a crooked RedLine: Analyzing the infamous infostealer’s backend. Retrieved September 17, 2025.
  2. Kroll RedLine Stealer August 2024 Open source
    George Glass. (2024, August 14). REDLINESTEALER Malware Driving the Initial Access Broker Market. Retrieved September 17, 2025.
  3. Proofpoint RedLine Stealer March 2020 Open source
    Proofpoint Threat Insight Team, Jeremy H, Axel F. (2020, March 16). New Redline Password Stealer Malware. Retrieved September 17, 2025.
  4. Splunk RedLine Stealer June 2023 Open source
    Splunk Threat Research Team. (2023, June 1). Do Not Cross The 'RedLine' Stealer: Detections and Analysis. Retrieved September 17, 2025.
  5. Veriti RedLine Stealer MAAS April 2023 Open source
    Yair Herling. (2023, April 4). From ChatGPT to RedLine Stealer: The Dark Side of OpenAI and Google Bard. Retrieved September 17, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.