logo

Redline Stealer Spreads Through Fake VPN Sites

ID: ffb38253-9258-5752-b296-9fc73e6b7966

STIX ID: report--ffb38253-9258-5752-b296-9fc73e6b7966

Feed Name: Cyble Blog

Threat Score
72/100

Date Published: 2025-11-27

Date Updated: 2026-07-17

...
...

Cyble Research & Intelligence Labs observed a phishing campaign using ExpressVPN look-alike domains and shortened Cuttly URLs that redirect to Discord-hosted Setup.zip, which contains a padded setup.exe that deploys Redline Stealer by injecting into jsc.exe; the stealer fetches configuration from net.tcp://109.107.191.169:34067 and exfiltrates credentials, cookies, crypto-wallet data and other sensitive information. Indicators of compromise (malicious domains, hashes, and C2 URL) and defensive recommendations (block URLs, use MFA, update software, monitor network beacons) are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.