ATT&CKReferencesKroll RedLine Stealer August 2024

Kroll RedLine Stealer August 2024

George Glass. (2024, August 14). REDLINESTEALER Malware Driving the Initial Access Broker Market. Retrieved September 17, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareRedLine Stealer

RedLine Stealer can enumeate information about victims’ systems including IP addresses.

T1036
Masquerading
MalwareRedLine Stealer

RedLine Stealer malware has masqueraded as legitimate software such as "PDF Converter Software" which has been distributed through poisoned search engine results often resembling legitimate software lures with the combination of typo squatted domains.

T1082
System Information Discovery
MalwareRedLine Stealer

RedLine Stealer can collect information about the local system.

T1105
Ingress Tool Transfer
MalwareRedLine Stealer

RedLine Stealer has the ability download additional payloads.

T1204.002
Malicious File
MalwareRedLine Stealer

RedLine Stealer malware has been executed through the download of malicious files. RedLine Stealer has also lured users to install malware with an Install Wizard interface.

T1518.001
Security Software Discovery
MalwareRedLine Stealer

RedLine Stealer has identified installed antivirus software on the system.

T1539
Steal Web Session Cookie
MalwareRedLine Stealer

RedLine Stealer has stolen browser cookies and settings.

T1555
Credentials from Password Stores
MalwareRedLine Stealer

RedLine Stealer has obtained credentials from VPN services, FTP clients and Instant Messenger (IM)/Chat clients.

T1555.003
Credentials from Web Browsers
MalwareRedLine Stealer

RedLine Stealer was designed to steal sensitive information from web browsers, including credit card details, saved credentials, and autocomplete data. RedLine Stealer can also gather credentials from several browsers.

T1614
System Location Discovery
MalwareRedLine Stealer

RedLine Stealer has gathered detailed information about victims’ systems, such as IP addresses, and geolocation. RedLine Stealer has also checked the IP from where it was being executed and leveraged an opensource geolocation IP-lookup service.

T1657
Financial Theft
MalwareRedLine Stealer

RedLine Stealer has collected data from cryptocurrency wallets and harvested credit cards details from browsers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.