Malware.View on attack.mitre.org
RedLine Stealer is an information-stealer malware variant first identified in 2020. RedLine Stealer is a Malware as a Service (MaaS) and was reportedly sold as either a one-time purchase or a monthly subscription service. Information obtained from RedLine Stealer has been known to be sold on the deep and dark web to Initial Access Brokers (IABs), who use or resell the stolen credentials for further intrusions.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
RedLine Stealer has collected data stored locally including chat logs and files associated with chat services such as Steam, Discord, and Telegram. |
| T1012 Query Registry |
RedLine Stealer can query the Windows Registry. |
| T1016 System Network Configuration Discovery |
RedLine Stealer can enumeate information about victims’ systems including IP addresses. |
| T1027.002 Software Packing |
RedLine Stealer has used obfuscation tools such as DNGuard and Boxed App to pack their code. |
| T1027.010 Command Obfuscation |
RedLine Stealer has obfuscated scripts within text files used in execution. |
| T1027.013 Encrypted/Encoded File |
RedLine Stealer has encrypted and encoded configuration data with Base64 and XOR functions. |
| T1033 System Owner/User Discovery |
RedLine Stealer has obtained the username from the victim’s machine. |
| T1036 Masquerading |
RedLine Stealer malware has masqueraded as legitimate software such as "PDF Converter Software" which has been distributed through poisoned search engine results often resembling legitimate software lures with the combination of typo squatted domains. |
| T1041 Exfiltration Over C2 Channel |
RedLine Stealer has sent victim data to its C2 server or RedLine panel server. |
| T1053.005 Scheduled Task |
RedLine Stealer has achieved persistence via scheduled tasks. |
| T1059.003 Windows Command Shell |
RedLine Stealer has executed windows cmd using `ErrorHandler.cmd` to create scheduled tasks. |
| T1059.011 Lua |
RedLine Stealer malware has leveraged Lua bytecode to perform malicious behavior. |
| T1071.001 Web Protocols |
RedLine Stealer has utilized HTTP for C2 communications. RedLine Stealer has also conducted C2 communications to hardcoded C2 servers over HTTPS. RedLine Stealer has leveraged SOAP protocol for C2 communications. |
| T1082 System Information Discovery |
RedLine Stealer can collect information about the local system. |
| T1087.001 Local Account |
RedLine Stealer has collected account information from the victim’s machine. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.