Redline Stealer Spreads Through Fake VPN Sites
ID: ffb38253-9258-5752-b296-9fc73e6b7966
STIX ID: report--ffb38253-9258-5752-b296-9fc73e6b7966
Feed Name: Cyble Blog
Cyble Research & Intelligence Labs observed a phishing campaign using ExpressVPN look-alike domains and shortened Cuttly URLs that redirect to Discord-hosted Setup.zip, which contains a padded setup.exe that deploys Redline Stealer by injecting into jsc.exe; the stealer fetches configuration from net.tcp://109.107.191.169:34067 and exfiltrates credentials, cookies, crypto-wallet data and other sensitive information. Indicators of compromise (malicious domains, hashes, and C2 URL) and defensive recommendations (block URLs, use MFA, update software, monitor network beacons) are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
