Police hacks, disrupts Redline, Meta infostealer operations

Teilen:

The Dutch National Police, along with partner law enforcement agencies, has disrupted the operation of the Redline and Meta infostealers and has collected information that may unmask users who paid to leverage the infamous malware.

About Redline and Meta

Redline and Meta (aka MetaStealer) are infostealers, capable of exfiltrating a variety of sensitive information:

  • Info about the victims’ machine/OS (Windows and macOS)
  • Credentials, credit card data and browser history from web browsers
  • Access tokens for cryptocurrency wallets
  • Credentials for instant messaging and VPN applications, FTP clients, and more

Redline was first spotted in 2020 and has since become one of the most popular inforstealers out there. Meta landed in dark web markets in 2022, and has the added distinction of being a threat targeting macOS users (and businesses).

Both are distributed under a malware-as-a-service model, meaning that the criminals who develop the malware sell access to it and to infrastructure for deploying and using it to less skilled cyber criminals.

Operation Magnus

On a dedicated page naming the international law enforcement organizations that took part of Operation Magnus, the Dutch Police says – in video marketing style – that they’ve:

  • Gained full access to all Redline and Meta servers (“Did you know, actually, that they’re pretty much the same?”)
  • Gained access to the Redline and Meta source code, including the license servers, REST API servers, panels, stealers, and Telegram bots
  • Collected username, passwords, IP addresses, timestamps and registration date for the users of the two infostealers, including the VIP users

As proof, the video shows screenshots of various panels, source code, as well as law enforcement flipping through the licensing server panels, and usernames belonging to the users of the two tools.

Operation Magnus is obviously trying to replicate the slow “dripping” of positive announcements the NCA-led Operation Cronos delivered when disrupting the LockBit ransomware-as-a-service operation: the Operation Magnus page also shows a countdown promising more news in roughly 21 hours.

There is currently no mention of arrests related to the disruption or of customers that may have been identified, but – the video says – “involved parties will be notified, and legal actions are underway.”

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
9:01 pm, Jan. 31, 2025
Wetter-Symbol 7°C
L: 6° | H: 7°
overcast clouds
Luftfeuchtigkeit: 92 %
Druck: 1028 mb
Wind: 5 mph E
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:40 am
Sonnenuntergang: 4:47 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Tomorrow 9:00 pm
Wetter-Symbol
6° | 7°°C 0 mm 0% 8 mph 90 % 1030 mb 0 mm/h
So. Feb. 02 9:00 pm
Wetter-Symbol
2° | 8°°C 0 mm 0% 6 mph 86 % 1026 mb 0 mm/h
Mo. Feb. 03 9:00 pm
Wetter-Symbol
2° | 9°°C 0 mm 0% 5 mph 92 % 1027 mb 0 mm/h
Di. Feb. 04 9:00 pm
Wetter-Symbol
3° | 9°°C 0 mm 0% 9 mph 93 % 1028 mb 0 mm/h
Mi. Feb. 05 9:00 pm
Wetter-Symbol
4° | 8°°C 0.51 mm 51% 7 mph 86 % 1045 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
5° | 6°°C 0 mm 0% 5 mph 90 % 1028 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
5° | 6°°C 0 mm 0% 6 mph 84 % 1029 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 4 mph 80 % 1029 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 3 mph 79 % 1030 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 8 mph 71 % 1029 mb 0 mm/h
Tomorrow 3:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 6 mph 73 % 1027 mb 0 mm/h
Tomorrow 6:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 6 mph 73 % 1027 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
4° | 4°°C 0 mm 0% 6 mph 82 % 1026 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€97,848.52
-3.28%
Ethereum(ETH)
€3,190.45
2.27%
XRP(XRP)
€2.90
-3.48%
Fesseln(USDT)
€0.96
-0.06%
Solana(SOL)
€220.87
-4.03%
USDC(USDC)
€0.96
0.00%
Dogecoin(DOGE)
€0.313779
-1.82%
Shiba Inu(SHIB)
€0.000018
0.23%
Pepe(PEPE)
€0.000013
8.08%
Nach oben scrollen