Threat Advisories

RedLine Stealer Malware Analysis

Written by Cyber Florida SOCAP Team | August, 10, 2026

Published 03/10/2023

I. Targeted Entities

  • Opportunistic (any industry)

II. Introduction

RedLine Stealer is a malware family written in C# that harvests autocomplete data, such as saved credentials and financial information, from web browsers. It can also steal system information such as location, hardware configuration, and security software data.

III. Background Information

Redline Stealer (RLS) is a popular malware strain that operates on a malware-as-a-service (MaaS) model and is sold on underground forums for approximately $100 (Unnikrishnan). Cybercriminals can use this software to collect a wide range of sensitive data from Gecko- and Chromium-based web browsers. This data includes saved credentials, financial information, and cookies, which allow attackers to access various accounts ranging from social media to cryptocurrency wallets (Meskauskas).

Telemetry data collected by CloudSEK has detected the deployment of RLS via Regsvcs.exe on Windows systems. The contents of the Regsvcs.exe process, in a suspended state, are replaced by the loader using a process hollowing technique. This allows for the portable executable of RLS to be mapped into the Regsvcs.exe process, where thread contexts can be manipulated to point to RLS’s entry location. Once complete, RLS can masquerade as a legitimate process on the system (Unnikrishnan).

Fake software posing as legitimate software is often used to spread malware like RLS, and eSentire’s Threat Response Unit (eTRU) has observed such a case where RLS is being distributed via a fake version of AnyDesk (eSentire). The legitimate AnyDesk website was cloned into a malicious site, where a victim would download an installer as an ISO image file padded with junk data. This padding is used to bypass file size limitations imposed by sandboxes and antivirus software (eSentire). Once the victim runs the installer, several commands are executed to run obfuscated files that check for antivirus software, communicate with the attacker’s command-and-control servers, and read the victim’s data (eSentire).

RLS comes with several additional features beyond data theft, such as saved passwords. Its primary targets are the user’s desktop and documents directories, where it searches for cryptocurrency data, such as crypto wallets, via more than 40 browser extensions. It captures a desktop screenshot and collects Discord tokens and user data from Steam. Beyond financial data, RLS can retrieve system information such as username, processor and memory information, installed browsers and antivirus programs, and currently running processes (Unnikrishnan).

IV. Cyber Florida SOC Operations

After initial malware execution, Cyber Florida has observed multiple executables dropped by a self-extracting RAR file. These executables, 123.exe and 321.exe, work together to create two vbc.exe child processes that execute the malicious code. The process vbc.exe appears to attempt communication with targeted IP addresses and ports, and with one of those communications, Cyber Florida observed what appeared to be the creation of “bebra.exe,” but upon a hex content review of the file, only the ASCII string “Hello” was present. It is suspected that this process may be attempting to establish some form of communication and then, by design, leads to a program crash. A hypothesis is that the “bebra.exe” file may simply be a placeholder until the malware needs or wants actual binary content. A review of vbc.exe appears to be a legitimate binary that may have been abused and injected into. Vbc.exe is the Visual Basic Compiler and is used with the .NET Framework. Injecting into a known-good process may be a way for an attacker’s malware to evade detection. The vbc.exe processes did have portions of memory that had RWX (Read, Write, and Execute) permissions. These sections of memory contained binary data, and they were extracted and analyzed. Cyber Florida uploaded both files to VirusTotal, and the following binary file was already detected:

https://www.virustotal.com/gui/file/a82732b71779c41df6b105ffe98f385b53d6bd64d783d6cb3caac9be3270d783/details

However, the following was not seen on VirusTotal until Cyber Florida uploaded the file for review:

https://www.virustotal.com/gui/file/f179a2d8bc7ab6cd32a8c1f95988d77fb1381072ac92f099047f7395cae84115

Network Traffic

This communication was the first observed network connection from the victim system to a system potentially controlled by an attacker. The communication was to 65.21.213.208:3000. The TCP stream below shows a POST action to the system with no real content. The server replies with a “Hello” response. Of interest, the “bebra.exe” file identified in the victim’s AppData/Roaming folder was not a binary of any sort, and when viewed in a hex editor, it only had an ASCII string of “Hello”. Also, of interest about “bebra.exe” is that the Content-Type was application/x-msdownload, which is associated with a binary file.

  

The following communication was the second observed network connection from the victim system to a system potentially controlled by a potential attacker. The traffic was to 51.89.207.166:47909. The observed traffic appeared to have no successful connections made. However, this IP and the specified port have been identified as potentially malicious through other threat intelligence sources.

  

Similar Observations Seen From ArechClient2

In November 2022, the Cyber Florida SOC released a threat advisory on Arechclient2 and provided presentations on their analysis. During analysis of Arechclient2 a Base64 string containing, once de-obfuscated, various Chrome extensions associated to Crypto wallets. Arechclient2 and RedLine appear to have similar functionality, including stealing browser data like usernames, passwords, and other sensitive information, such as crypto wallet details. When analyzing the current version of RedLine, a similar Base64 string was found. The following string is base64-encoded data and its decoded result via CyberChef. This further shows similarity between the two malware variants.

Inject VBC 1 Process

The following shows metadata associated with the injected binary for the first VBC process. Of note is essentially the future timestamp value of the binary. Also, reviewing some of the content statically did not reveal as much data as reviewing it dynamically did. For example, attacker IP addresses and other key findings were not identified in a static manner. The binary appears to have been compiled in .NET, and the source code of the injected binary would be the next step for analysis.

  

The following string was extracted from ProcessHacker as the malware was running. This string shows the IP address and specified port of interest, along with the POST action observed in Wireshark. This activity also aligns with the ProcMon (ProcessMonitor) logs generated by this activity.

  

Inject VBC 2 Process

The following shows metadata associated with the injected binary for the second VBC process. Of note is essentially the no timestamp value of the binary. Also, reviewing some of the content statically did not reveal as much data as reviewing it dynamically did. For example, attacker IP addresses and other key findings were not identified in a static manner.

  

The following screenshots were taken from ProcessHacker as the malware was running. We can observe the IP address and the specified port of interest as strings, and they can also be represented in Base64.

  

Overall Order of VBC Activity

The following is a brief, high-level (non-exhaustive) order of events related to the execution of malicious activity by vbc.exe. Taken from ProcMon logs.

  

V. MITRE ATT&CK

  • T1005 – Data from Local System
    Adversaries may search local system sources, such as file systems, configuration files,  or local databases, to find files of interest and sensitive data prior to Exfiltration. Adversaries may do this using a Command-line Interface (CLI), such as cmd, as well as a Network Device CLI, which includes functionality to interact with the file system to gather information. Adversaries may also use Automated Collection on the local system.
  • T1012 – Query Registry
    Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software. The Registry contains a significant amount of information about the operating system, configuration, software, and security.[1] Information can be easily queried using the Reg utility, though other means of accessing the Registry exist. Some of the information may help adversaries to further their operation within a network. Adversaries may use information from the Query Registry during automated discovery to shape follow-on behaviors, including whether the adversary fully infects the target and/or attempts specific actions.
  • T1552.001 – Unsecured Credential; Credentials in Files
    Adversaries may attempt to capture desktop screens to gather information over the course of an operation. Screen-capturing functionality may be included in a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls.
  • T1082 – System Discovery
    An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use information from System Information Discovery during automated discovery to shape follow-on behaviors, including whether the adversary fully infects the target and/or attempts specific actions.
  • T1055 – Process Injection
    Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process’s memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection by security products, as it is masked by a legitimate process.
  • T1095 –Non-Application Layer Protocol
    Adversaries may use a non-application-layer protocol to communicate between a host and a C2 server, or among infected hosts within a network. The list of possible protocols is extensive
  • T1059 – Command and Scripting Interpreter
    Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways to interact with computer systems and are common across many platforms. Most systems come with built-in command-line interfaces and scripting capabilities; for example, macOS and Linux distributions include a flavor of Unix Shell, while Windows installations include the Windows Command Shell and PowerShell.

VI. Recommendations

  • Phishing awareness training
    Users should be informed and educated about new phishing scams currently being used and those used in the past. Awareness training should instruct users to avoid suspicious emails, links, websites, attachments, etc. Users should also be educated about new types of attacks and schemes to mitigate risk. Recommended link: https://www.us-cert.gov/ncas/tips/ST04-014
  • Set antivirus programs to conduct regular scans
    Ensure that antivirus and antimalware programs are scanning assets using up-to-date signatures
  • Malware monitoring
    Continuously monitor current and new types of malware. Stay up to date on intel and advancements to prevent, defend, and mitigate these types of threats.
  • Strong cyber hygiene
    Enforce a strong password policy across all networks and subsystems. Remind users to be wary of any messages asking for immediate attention, links, downloads, etc. All sources should be verified. Recommended link: https://us-cert.cisa.gov/ncas/alerts/aa21-131a
  • Turn on endpoint protection
    Enable endpoint detection and response (EDR) to stop unknown malware in the product you’re using.
  • Network Monitoring
    Review network logs, payload, etc., for related IP addresses and associated network parameters.

VII. Indicators of Compromise (IOCs)

  

  

  

VII. Additional OSINT Information

4efdf3a4c19a94b2e58f5212124cb161.exe
Note: the initial executable may have a different file name.

123.exe
https://www.virustotal.com/gui/file/d3b64baa18214715f544c836b59e2ca839e86 95f93706476033a1e8c56dd7287

321.exe
https://www.virustotal.com/gui/file/aadbf6b7fd77075e6355a209c4cbd8b1049f21eb69f503203bd6fd7a7a085dc6

Vbc.exe.bin (injected 1 process)
https://www.virustotal.com/gui/file/a82732b71779c41df6b105ffe98f385b53d6bd64d783d6cb3caac9be3270d783

Vbc.exe2.bin (injected 2 processes)
https://www.virustotal.com/gui/file/f179a2d8bc7ab6cd32a8c1f95988d77fb1381072ac92f099047f7395cae84115?nocache=1

IX. References

eSentire. Entire Threat Intelligence Malware Analysis: Redline Stealer. eSentire. (n.d.). Retrieved February 10, 2023, from https://www.esentire.com/blog/esentire-threat-intelligence-malware-analysis-redline-stealer

Meskauskas, T. (2023, February 1). Redline Stealer malware. RedLine Stealer Malware – Malware removal instructions (updated). Retrieved February 10, 2023, from https://www.pcrisk.com/removal-guides/17280-redlinestealer-malware

Unnikrishnan, A., & CloudSEk. (2023, January 26). Technical analysis of the redline stealer: CloudSEK. RSS. Retrieved February 10, 2023, from https://cloudsek.com/blog/technical-analysis-of-the-redline-stealer

 Contributing Security Analysts: Sreten Dedic, EJ Bulut