Infostealers and the hackers who use them evolve to stay ahead of security measures. They adapt quickly to exploit new vulnerabilities and techniques, making it challenging for defenders to keep up.
Today(7 Nov 2023), researchers from Any Run saw again its activity that steals data, causes financial loss, and targets both enterprise and personal devices.
ANY.RUN is an interactive malware sandbox that allows users to analyze an unlimited number of malicious files and links for free.
The rapid evolution of info stealers enables threat actors to target various illicit purposes, from stealing personal information to financial fraud and espionage.
RedLine Stealer is a versatile malware that causes financial loss and data leaks. It targets the healthcare and manufacturing sectors, emerged in March 2020, gained momentum during COVID-19, and still thrives.
On July 1st, 2021, it was discovered on a deceptive website offering privacy tools, but it only delivered malware.
RedLine infostealer swipes user info, including passwords, credit cards, and hardware details. It behaves like Raccoon or Pony, enabling file transfers and executing commands; besides this, threat actors deploy it for:-
RedLine Stealer, easily accessible on underground forums, comes in service and subscription models, priced from $100 to $200.
While not as sophisticated as ransomware, it’s a high-quality .Net malware written by an experienced programmer. Threat actors continuously update it with secondary payloads and advanced filtering.
The stealer’s execution process is usually straightforward, where the main binary takes over, sometimes replacing the parent process or being dropped by another binary.
RedLine starts gathering private information from the infected system when a child process spawns and delivers it to the Command & Control panel.
After gathering and transmitting data, the stealer terminates, and then the stolen info is sent in both the following formats:-
Attackers lack creativity in the virus delivery, but their tried-and-true methods, like social engineering in email campaigns, fake updates, and spam, are effective.
Apart from this, they use various file formats, and here below we have mentioned them:-
Protecting against RedLine involves vigilance with email attachments and links. Even trusted sources can lead to infection and credential theft.
You can expand your SIEM and other security systems by integrating IOCs directly from ANY.RUN sandbox.
Implementing ANY.RUN’s Threat Intelligence products are simple. Contact the company’s sales team to learn more.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…