Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
Infostealer

RedLine Stealer

Infostealer 23 detections found

Also known as: RedLine, RedLine InfoStealer, RedLine Info Stealer

RedLine Stealer is a Windows information-stealing malware, active since 2020, sold as malware-as-a-service via one-time purchases or monthly subscriptions on underground forums. It harvests credentials, cookies, and autofill data from browsers, plus cryptocurrency wallet and messaging-app data, which is frequently resold to initial access brokers. On October 28, 2024, an international operation (Operation Magnus, DOJ, Dutch National Police, and partners in the UK, Belgium, Portugal, and Australia) seized RedLine's and its sibling META's backend infrastructure and source code, and the U.S. charged alleged developer/administrator Maxim Rudometov; despite this, RedLine and its offshoots continue to see some residual activity.

Detection & eradication references

Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.

Detection rules

Source Rule Status Updated
splunk Windows Modify Registry wuStatusServer production 2026-05-13
splunk Windows Modify Registry UpdateServiceUrlAlternate production 2026-05-13
splunk Windows Modify Registry USeWuServer production 2026-05-13
splunk Windows Modify Registry WuServer production 2026-05-13
splunk Windows Spearphishing Attachment Onenote Spawn Mshta production 2026-05-13
splunk Windows Modify Registry Auto Minor Updates production 2026-05-13
splunk Windows Modify Registry Auto Update Notif production 2026-05-13
splunk Windows Modify Registry Disable WinDefender Notifications production 2026-05-13
splunk Windows Modify Registry Do Not Connect To Win Update production 2026-05-13
splunk Windows Modify Registry No Auto Reboot With Logon User production 2026-05-13
splunk Windows Modify Registry No Auto Update production 2026-05-13
suricata ET MALWARE RedLine - GetArguments Request rev 2 2024-04-24
suricata ET MALWARE Redline Stealer TCP CnC Activity rev 2 2024-03-08
snort ET TROJAN RedLine Stealer - CheckConnect Response rev 3 2023-12-13
suricata ET MALWARE RedLine Stealer - CheckConnect Response rev 3 2023-12-13
suricata ET MALWARE Redline Stealer TCP CnC Activity rev 1 2023-06-06
suricata ET MALWARE Redline Stealer Stager WebPage Inbound rev 1 2023-06-06
snort ET TROJAN Redline Stealer TCP CnC Activity rev 1 2023-06-06
snort ET ATTACK_RESPONSE Redline Stealer Stager WebPage Inbound rev 1 2023-06-06
snort ET MALWARE Redline Stealer TCP CnC - Id1Response rev 1 2023-01-06
suricata ET MALWARE Redline Stealer TCP CnC - Id1Response rev 2 2023-01-06
snort ET TROJAN Redline Stealer TCP CnC Activity rev 1 2023-01-06
snort ET TROJAN RedLine - GetArguments Request rev 2 2021-04-14