ATT&CKReferencesSplunk RedLine Stealer June 2023

Splunk RedLine Stealer June 2023

Splunk Threat Research Team. (2023, June 1). Do Not Cross The 'RedLine' Stealer: Detections and Analysis. Retrieved September 17, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareRedLine Stealer

RedLine Stealer has encrypted and encoded configuration data with Base64 and XOR functions.

T1033
System Owner/User Discovery
MalwareRedLine Stealer

RedLine Stealer has obtained the username from the victim’s machine.

T1071.001
Web Protocols
MalwareRedLine Stealer

RedLine Stealer has utilized HTTP for C2 communications. RedLine Stealer has also conducted C2 communications to hardcoded C2 servers over HTTPS. RedLine Stealer has leveraged SOAP protocol for C2 communications.

T1082
System Information Discovery
MalwareRedLine Stealer

RedLine Stealer can collect information about the local system.

T1087.001
Local Account
MalwareRedLine Stealer

RedLine Stealer has collected account information from the victim’s machine.

T1102
Web Service
MalwareRedLine Stealer

RedLine Stealer has leveraged legitimate file sharing web services to host malicious payloads.

T1113
Screen Capture
MalwareRedLine Stealer

RedLine Stealer can capture screenshots on a compromised host.

T1140
Deobfuscate/Decode Files or Information
MalwareRedLine Stealer

RedLine Stealer has decoded its payload prior to execution.

T1217
Browser Information Discovery
MalwareRedLine Stealer

RedLine Stealer can collect information from browsers and browser extensions.

T1497
Virtualization/Sandbox Evasion
MalwareRedLine Stealer

RedLine Stealer has an anti-sandbox technique that requires the malware to consistently check with the C2 server, if the communication fails RedLine Stealer will not continue execution.

T1518
Software Discovery
MalwareRedLine Stealer

RedLine Stealer can get a list of programs on the victim device.

T1539
Steal Web Session Cookie
MalwareRedLine Stealer

RedLine Stealer has stolen browser cookies and settings.

T1555
Credentials from Password Stores
MalwareRedLine Stealer

RedLine Stealer has obtained credentials from VPN services, FTP clients and Instant Messenger (IM)/Chat clients.

T1555.003
Credentials from Web Browsers
MalwareRedLine Stealer

RedLine Stealer was designed to steal sensitive information from web browsers, including credit card details, saved credentials, and autocomplete data. RedLine Stealer can also gather credentials from several browsers.

T1614.001
System Language Discovery
MalwareRedLine Stealer

RedLine Stealer can retrieve system default language and time zone.

T1657
Financial Theft
MalwareRedLine Stealer

RedLine Stealer has collected data from cryptocurrency wallets and harvested credit cards details from browsers.

T1685
Disable or Modify Tools
MalwareRedLine Stealer

RedLine Stealer can disable security software and update services.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.