• Latest
  • Trending
  • All
  • BUSINESS
  • ENTERTAINMENT
  • POLITICAL
  • TECHNOLOGY
ESET shines light on cyber criminal RedLine empire

ESET shines light on cyber criminal RedLine empire

November 9, 2024
NYPD condemns Trump’s DHS for playing politics with counterterrorism funds

NYPD condemns Trump’s DHS for playing politics with counterterrorism funds

October 2, 2025
Morocco: The 14th edition of the Magreb International Film Festival opens in Oujda

Morocco: The 14th edition of the Magreb International Film Festival opens in Oujda

October 2, 2025
South Korea airport workers go on strike starting Wednesday, Korea Airports Corp says, Asia News

South Korea airport workers go on strike starting Wednesday, Korea Airports Corp says, Asia News

October 2, 2025
Mike Johnson Caught on Camera Admitting Trump Is ‘Unwell’

Mike Johnson Caught on Camera Admitting Trump Is ‘Unwell’

October 2, 2025
Madagascar: Protests ongoing to demand president’s resignation as police presence grows

Madagascar: Protests ongoing to demand president’s resignation as police presence grows

October 2, 2025
ICA foils attempt to smuggle 9,200 e-vaporiser pods declared as power banks, 25-year-old Singaporean man arrested, Singapore News

ICA foils attempt to smuggle 9,200 e-vaporiser pods declared as power banks, 25-year-old Singaporean man arrested, Singapore News

October 2, 2025

Pope makes rare comments on U.S. politics, military gathering

October 2, 2025
DRC: Joseph Kabila’s death sentence sends shockwaves through Goma

DRC: Joseph Kabila’s death sentence sends shockwaves through Goma

October 2, 2025
Former lovers acquitted of all charges over alleged sexual abuse of woman’s daughter, Singapore News

Former lovers acquitted of all charges over alleged sexual abuse of woman’s daughter, Singapore News

October 2, 2025
A government shutdown role reversal: From the Politics Desk

A government shutdown role reversal: From the Politics Desk

October 2, 2025
Athens paralyzed by general strike against new labor laws

Athens paralyzed by general strike against new labor laws

October 2, 2025
Nicole Kidman and Keith Urban separate after nearly 2 decades together, Entertainment News

Nicole Kidman and Keith Urban separate after nearly 2 decades together, Entertainment News

October 2, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Wednesday, January 21, 2026
No Result
View All Result
  • HOME
  • BUSINESS
  • ENTERTAINMENT
  • POLITICAL
  • TECHNOLOGY
  • ABOUT US
  • OUR POLICY
  • Login
  • Register
  • HOME
  • BUSINESS
  • ENTERTAINMENT
  • POLITICAL
  • TECHNOLOGY
  • ABOUT US
  • OUR POLICY
No Result
View All Result
Huewire
No Result
View All Result
Home TECHNOLOGY

ESET shines light on cyber criminal RedLine empire

by huewire
November 9, 2024
in TECHNOLOGY
0
ESET shines light on cyber criminal RedLine empire
498
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter

valerybrozhinsky – stock.adobe.c

ESET publishes fresh data on the inner workings of the RedLine Stealer malware empire, which was taken down at the end of October

Alex Scroxton

By

  • Alex Scroxton,
    Security Editor

Published: 08 Nov 2024 16:45

Cyber security analysts at ESET have released an in-depth look at the inner workings of the RedLine Stealer operation and its clone, known as Meta, in the wake of a Dutch-led operation that saw the cyber criminal empire laid low.

Operation Magnus saw the Dutch National Police force, working with European Union support and other agencies including the FBI and the UK’s National Crime Agency (NCA), dismantle the infamous infostealers’ infrastructure.

The action was the culmination of a lengthy investigation to which ESET – which initially notified the authorities in the Netherlands that some of the malwares’ infrastructure was being hosted in their jurisdiction – was a key contributor, taking part in a preliminary operation last year that targeted the gang’s ability to use GitHub repositories as a “dead-drop” control mechanism.

In an extensive dossier, ESET said that having conducted an extensive analysis of the malwares’ source code and backend infrastructure in the run-up to Operation Magnus, it was now able to confirm with certainty that both Redline and Meta did indeed share the same creator, and identified well over 1,000 unique IP addresses that had been used to control the operation.

“We were able to identify over 1,000 unique IP addresses used to host RedLine control panels,” said ESET researcher Alexandre Côté Cyr.

“While there may be some overlap, this suggests on the order of 1,000 of subscribers to the RedLine MaaS [malware as a service],” he added.

“The 2023 versions of RedLine Stealer ESET investigated in detail used the Windows Communication Framework for communication between the components, while the latest version from 2024 uses a REST API.”

Global operation

The IP addresses found by ESET were dispersed globally, although mostly in Germany, the Netherlands and Russia, all accounting for about 20% of the total. Approximately 10% were located in Finland and the US.

ESET’s investigation also identified multiple distinct backend servers, with about 33% in Russia, and Czechia, the Netherlands and the UK all accounting for about 15%.

What was RedLine Stealer?

Ultimately, the goal of the RedLine and Meta operations was to harvest vast amounts of data from its victims, including information on cryptocurrency wallets, credit card details, saved credentials, and data from platforms including desktop VPNs, Discord, Telegram and Steam.

The operators’ clients bought access to the product, described by ESET in corporate terms as a “turnkey infostealer solution”, through various online forums or Telegram channels. They could select either a monthly rolling subscription or a lifetime licence, and in exchange for their money received a control panel to generate malware samples and act as a personal command and control server.

“Using a ready-made solution makes it easier for the affiliates to integrate RedLine Stealer into larger campaigns,” said Côté Cyr. “Some notable examples include posing as free downloads of ChatGPT in 2023 and masquerading as video game cheats in the first half of 2024.”

At its peak, prior to the takedown, RedLine was probably the most widespread infostealer in operation, with a comparatively large number of affiliates. However, said ESET, the MaaS enterprise was likely orchestrated by a very small number of people.

Crucially, the creator of the malwares, named as Maxim Rudometov, has been identified and charged in the US.

Read more on Hackers and cybercrime prevention


  • RedLine, Meta malwares meet their demise at hands of Dutch cops

    AlexScroxton

    By: Alex Scroxton


  • More than 160 Snowflake customers hit in targeted data theft spree

    AlexScroxton

    By: Alex Scroxton


  • Mandiant: ‘Exposed credentials’ led to Snowflake attacks

    AlexanderCulafi

    By: Alexander Culafi


  • Data on over 3,000 Airbus suppliers leaked after breach

    AlexScroxton

    By: Alex Scroxton

Read More

Share199Tweet125
huewire

huewire

Recent Comments

No comments to show.

Recent Posts

  • NYPD condemns Trump’s DHS for playing politics with counterterrorism funds
  • Morocco: The 14th edition of the Magreb International Film Festival opens in Oujda
  • South Korea airport workers go on strike starting Wednesday, Korea Airports Corp says, Asia News
  • Mike Johnson Caught on Camera Admitting Trump Is ‘Unwell’
  • Madagascar: Protests ongoing to demand president’s resignation as police presence grows
Huewire

Copyrights © 2025 Huewire.com.

Navigate Site

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Follow Us

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • HOME
  • BUSINESS
  • ENTERTAINMENT
  • POLITICAL
  • TECHNOLOGY
  • ABOUT US
  • OUR POLICY

Copyrights © 2025 Huewire.com.