Technical Analysis of the RedLine Stealer
ID: 790a95d4-516a-5591-8693-14c209efdd33
STIX ID: report--790a95d4-516a-5591-8693-14c209efdd33
Feed Name: CloudSEK Blog
Threat Score
**Executive summary:** This report provides a technical analysis of the RedLine information stealer (a malware-as-a-service infostealer) describing its deployment via process hollowing of Regsvcs.exe, built-in configuration and decoding routines, region checks, capabilities to steal browser credentials, crypto wallets, files, screenshots, and to execute additional payloads, along with C2 communication patterns and IoCs (hashes, IPs, domains) to aid detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
