RedLine Stealer

 

RedLine Stealer, initially identified in March 2020, stands out as a prominent malware known for its theft capabilities. Positioned as a sought-after commodity in the cyber underworld, it is marketed as Malware-as-a-Service (MaaS). The appeal of RedLine Stealer lies in its widespread availability and adaptability. This malicious software is engineered to extract sensitive data from compromised systems.

Its primary focus is on pilfering information from web browsers, including but not limited to saved login credentials and payment card details. Beyond this, RedLine Stealer conducts a comprehensive sweep of the target system, gathering data such as usernames, hardware configurations, installed software (both general and security-oriented), presence of VPN clients, network configurations, and even data related to cryptocurrencies. Subsequently, the pilfered information is discreetly transmitted to the malicious actors orchestrating the attack.

Target OS 

  • Windows XP to Windows 11, both 32-64 bit, including Server editions.

Infection Vector

RedLine Stealer employs a variety of tactics to infiltrate systems, posing a formidable challenge for detection and prevention. These methods encompass spear-phishing campaigns, watering hole attacks, exploiting vulnerabilities in applications, malvertising, deceptive software upgrades or installers, enticing YouTube video links, and illicit downloads of pirated software. Furthermore, the malware is introduced into systems through loader malware like PureCrypter and SYK Crypter, acting as gateways for the malicious payload. The amalgamation of these diverse distribution strategies not only complicates the identification process but also heightens the risk for victims who unwittingly fall victim to RedLine Stealer, exposing them to potentially severe consequences.

Identification

  • C2 Communication
    • 193[.]233[.]132.4[:]1285
  • Behavior
    • "http://tempuri.org/RestAPI/TreeObject2Response"
    • "http://tempuri.org/Entity/Id2"
  • Strings
    • "RedLine.IRemotePanel"
    • "RedLine.Logic.ImClient"
    • "RedLine.Client"

MITRE ATT&CK

  •  T1082 - System Information Discovery
  • T1083 - File and Directory Discovery
  • T1033 - System Owner/User Discovery 
  • T1047 - Windows Management Instrumentation
  • T1115 - Clipboard Data

Evasion techniques

  • Obfuscated Files or Information - To evade detection, Redline compression, archiving, or encryption techniques. This process helps conceal the true nature of the payload, making it more challenging for detection systems to identify and analyze its contents.
  • Deobfuscate/Decode Files or Information - Redline hide its artifacts of an intrusion from analysis.

IOC's

  • Hash
    • 974fc8f85409d4897e369e2b15994932
    • c883e3d92191007804a5c69f5c854ca0
    • 1a547597c64963fd8155a6593c279cb9
    • 7b2a381f44b093dffa23c27f7eb99ef2
  • C2 
    • 193[.]233.132.4[:]62111 
    • 45.15[.]156.45[:]80
    • 193.233[.]132.34[:]16479 
    • 135[.]181.13.134[:]8395
for more IOC
  

 

Comments