logo

New RedLine Stealer Variant Disguised as Game Cheats Using Lua Bytecode for Stealth

ID: 3572cb48-4e7a-5c48-a9ce-0a8076e7d367

STIX ID: report--3572cb48-4e7a-5c48-a9ce-0a8076e7d367

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2024-04-21

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

A RedLine Stealer variant has been observed using Lua bytecode and weaponized GitHub uploads to distribute malicious ZIP archives (masquerading as game cheats) that install an MSI which runs embedded Lua bytecode, establishes persistence, and communicates with a RedLine-associated C2 to perform info-stealing and backdoor tasks; the report highlights abuse of a GitHub issue-upload bug and related TTPs targeting the gaming community.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.