Redline Stealer: A Novel Approach
ID: 41e6b147-5ab6-520c-acfc-3ec7826638b0
STIX ID: report--41e6b147-5ab6-520c-acfc-3ec7826638b0
Feed Name: infostealers.com
A new packed variant of the RedLine Stealer was distributed via a trojanised GitHub-hosted MSI (Cheat.Lab.2.7.2.zip). The installer drops a LuaJIT-based payload (compiler.exe + lua51.dll + readme.txt containing Lua bytecode), establishes persistence via scheduled tasks and an ErrorHandler.cmd launched by oobe\Setup.exe, collects system identifiers and screenshots, and communicates with an HTTP C2 (noted IP 213.248.43.58) to exfiltrate data; McAfee telemetry reports infections across multiple continents and the report includes multiple file hashes and URLs as IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
