Threats Tagged 'redline stealer'
View all threats tagged with 'redline stealer'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'redline stealer'
Click on any threat for detailed analysis and mitigation recommendations
0 An investigation beginning with a single RedLine Stealer C2 server from VMRay UniqueSignal evolved into uncovering a targeted Business Email Compromise campaign against South Korean maritime infrastructure. The analysis started with IP 194.156.79.122 on port 55615, leveraging fingerprinting techniques through FOFA and VirusTotal to identify additional C2 infrastructure. Pivoting through communicating files revealed spear-phishing emails targeting Kangrim Heavy Industries, a major South Korean marine boiler manufacturer. The campaign delivered Formbook malware through impersonated maritime supply chain companies. Further infrastructure analysis identified seven fraudulent domains hosted on TheHost LLC infrastructure, utilizing similar naming patterns and TLS certificates. The attack demonstrates sophisticated BEC tactics combining malware delivery with social engineering, mimicking legitimate business correspondence within the maritime shipping sector. Join the discussion | AlienVault OTX General | 07/02/2026, 11:29:26 UTC Added: 07/02/2026, 11:36:39 UTC |
Insikt Group identified five distinct clusters using the ClickFix social engineering technique for initial access. These clusters impersonate various services like Intuit QuickBooks and Booking.com, demonstrating operational variance but similar core techniques. ClickFix manipulates victims into executing malicious commands within native system tools, bypassing traditional security controls. The methodology has become a standardized template for cybercriminals and APT groups. Campaigns target diverse sectors and use sophisticated obfuscation and living-off-the-land tactics. Defenders are advised to implement aggressive behavioral hardening and user awareness training to mitigate these threats. Join the discussion | AlienVault OTX General | 03/25/2026, 21:48:17 UTC Added: 03/25/2026, 22:01:46 UTC |
The German hosting provider aurologic GmbH has become a critical infrastructure hub for multiple high-risk and sanctioned cybercrime networks, including entities involved in disinformation and malware campaigns. Despite public scrutiny and sanctions, aurologic continues to provide upstream transit services, enabling threat actors to maintain operational stability. The provider's approach to abuse handling is reactive and legally compliant rather than proactive, allowing malicious infrastructure to persist. This situation highlights challenges in accountability within the hosting ecosystem and the risks posed by infrastructure neutrality when it enables cybercrime. Numerous suspicious domains linked to aurologic-hosted networks have been identified, associated with malware families and threat actor tools. European organizations, especially in Germany, face increased risks due to this infrastructure's stability and continued operation. Mitigation requires enhanced monitoring of traffic from these domains, collaboration with upstream providers, and pressure on hosting providers to adopt proactive abuse prevention. Countries with significant internet infrastructure and cybercrime targets in Europe are most likely to be affected. Join the discussion | AlienVault OTX General | 11/06/2025, 18:51:59 UTC Added: 11/06/2025, 20:20:40 UTC |
Showing 1 to 3 of 3 results