Redline Stealer: A Novel Approach
ID: 529499c5-11d5-53ee-ae6e-c3123f632f45
STIX ID: report--529499c5-11d5-53ee-ae6e-c3123f632f45
Feed Name: McAfee Labs Blog
This report documents a widespread RedLine stealer variant distributed via a trojanized GitHub-hosted MSI (Cheat.Lab.2.7.2.zip) that executes LuaJIT bytecode to perform credential and data theft. The analysis details the infection chain, runtime compilation/execution of Lua bytecode, persistence (scheduled tasks, copying to ProgramData, Windows Setup error handler), HTTP-based C2 that receives tasks and accepts exfiltrated screenshots and system metadata, and supplies IoCs (file hashes, malicious URLs, and a C2 IP) for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
