logo

A Deep-dive Analysis of RedLine Stealer Malware

ID: 457539a3-d098-5387-bb9a-566aa5940197

STIX ID: report--457539a3-d098-5387-bb9a-566aa5940197

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2021-08-12

Date Updated: 2026-07-20

...
...

Cyble Research Lab presents a technical analysis of RedLine Stealer, an actively marketed stealer malware sold via Telegram that collects browser credentials, cookies, system and hardware details, VPN and wallet credentials and exfiltrates them to attacker C2 servers; the report documents static/decompiled findings, runtime process and network behavior (including C2 domain newlife957.duckdns.org:7225 and DNS lookups to api.ip.sb), XML-based C2 protocol, configuration tags, sample victim data fields, multiple SHA-256 sample hashes, and recommended defensive measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.