ATT&CKReferencesMcAfee RedLine Stealer April 2024

McAfee RedLine Stealer April 2024

Mohansundaram M, Neil Tyagi. (2024, April 17). Redline Stealer: A Novel Approach. Retrieved September 17, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareRedLine Stealer

RedLine Stealer can query the Windows Registry.

T1027.010
Command Obfuscation
MalwareRedLine Stealer

RedLine Stealer has obfuscated scripts within text files used in execution.

T1053.005
Scheduled Task
MalwareRedLine Stealer

RedLine Stealer has achieved persistence via scheduled tasks.

T1059.003
Windows Command Shell
MalwareRedLine Stealer

RedLine Stealer has executed windows cmd using `ErrorHandler.cmd` to create scheduled tasks.

T1059.011
Lua
MalwareRedLine Stealer

RedLine Stealer malware has leveraged Lua bytecode to perform malicious behavior.

T1071.001
Web Protocols
MalwareRedLine Stealer

RedLine Stealer has utilized HTTP for C2 communications. RedLine Stealer has also conducted C2 communications to hardcoded C2 servers over HTTPS. RedLine Stealer has leveraged SOAP protocol for C2 communications.

T1113
Screen Capture
MalwareRedLine Stealer

RedLine Stealer can capture screenshots on a compromised host.

T1132.001
Standard Encoding
MalwareRedLine Stealer

RedLine Stealer has used Base64 to encode command and control traffic.

T1204.002
Malicious File
MalwareRedLine Stealer

RedLine Stealer malware has been executed through the download of malicious files. RedLine Stealer has also lured users to install malware with an Install Wizard interface.

T1218.007
Msiexec
MalwareRedLine Stealer

RedLine Stealer has been installed via MSI Installer.

T1614
System Location Discovery
MalwareRedLine Stealer

RedLine Stealer has gathered detailed information about victims’ systems, such as IP addresses, and geolocation. RedLine Stealer has also checked the IP from where it was being executed and leveraged an opensource geolocation IP-lookup service.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.