US charges suspected Redline infostealer developer, admin

Share:

The identity of a suspected developer and administrator of the Redline malware-as-a-service operation has been revealed: Russian national Maxim Rudometov.

Infrastructure takedown

As promised on Monday when they announced the disruption of the Redline and Meta infostealer operations, law enforcement Operation Magnus has unveiled on Tuesday how the takedown played out.

“Investigations into Redline and Meta started after victims came forward and a security company notified authorities about possible servers in the Netherlands linked to the software. Authorities discovered that over 1,200 servers in dozens of countries were running the malware,” shared Eurojust, the European Union Agency for Criminal Justice Cooperation.

Eurojust coordinated the information exchange between and actions taken by authorities from the Netherlands, the United States, Belgium, Portugal, United Kingdom and Australia, which resulted in three servers taken down in the Netherlands, two seized domains, the disruption of several Redline and Meta communication channels (Telegram), and two people – suspected customers of Rudometov’s – being taken into custody in Belgium.

“The authorities also retrieved a database of clients from Redline and Meta. Investigations will now continue into the criminals using the stolen data,” Eurojust added.

The security company mentioned in the latest announcements is ESET, which also made available a scanner that Windows users can leverage to check whether they’ve been infected with the Redline or Meta stealers and to remove the malware (if present).

It is estimated that the Redline and Meta infostealers stole information from millions of victims around the world.

Pinpointing the person behind the operation

Law enforcement managed to connect various online monikers and email addresses used by Rudometov over the years on hacking forums and link some to a VK (Russian social network) account in that name.

“A judicially-authorized search of [the Apple account registered with one of those email addresses] revealed an associated iCloud account and numerous files that were identified by antivirus engines as malware, including at least one that was analyzed by the Department of Defense Cybercrime Center (‘DC3’) and determined to be Redline,” the unsealed criminal complaint against Rudometov says.

“Notably, among the malicious files saved to Rudometov’s Apple iCloud Drive was a file entitled ‘MysteryPanel.rar’ which correlates to the [Redline infostealer]. In addition to the registration information indicating Rudometov was the owner of the Apple account, the account contained photos that included Rudometov’s official identification documents and apparent personal photos.”

He has also been tied with a number of cryptocurrency accounts that were used to receive and launder payments, and the malware was hosted on servers controlled and accessed by him.

Rudometov has been charged by the US Department of Justice with access device fraud, conspiracy to commit computer intrusion, and money laundering.

The DOJ press release does not mention whether Rudometov is in police custody, which means he’s most likely not.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
9:02 pm, Jan 31, 2025
weather icon 7°C
L: 6° | H: 7°
overcast clouds
Humidity: 92 %
Pressure: 1028 mb
Wind: 5 mph E
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:40 am
Sunset: 4:47 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 9:00 pm
weather icon
6° | 7°°C 0 mm 0% 8 mph 90 % 1030 mb 0 mm/h
Sun Feb 02 9:00 pm
weather icon
2° | 8°°C 0 mm 0% 6 mph 86 % 1026 mb 0 mm/h
Mon Feb 03 9:00 pm
weather icon
2° | 9°°C 0 mm 0% 5 mph 92 % 1027 mb 0 mm/h
Tue Feb 04 9:00 pm
weather icon
3° | 9°°C 0 mm 0% 9 mph 93 % 1028 mb 0 mm/h
Wed Feb 05 9:00 pm
weather icon
4° | 8°°C 0.51 mm 51% 7 mph 86 % 1045 mb 0 mm/h
Tomorrow 12:00 am
weather icon
5° | 6°°C 0 mm 0% 5 mph 90 % 1028 mb 0 mm/h
Tomorrow 3:00 am
weather icon
5° | 6°°C 0 mm 0% 6 mph 84 % 1029 mb 0 mm/h
Tomorrow 6:00 am
weather icon
5° | 5°°C 0 mm 0% 4 mph 80 % 1029 mb 0 mm/h
Tomorrow 9:00 am
weather icon
5° | 5°°C 0 mm 0% 3 mph 79 % 1030 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
6° | 6°°C 0 mm 0% 8 mph 71 % 1029 mb 0 mm/h
Tomorrow 3:00 pm
weather icon
6° | 6°°C 0 mm 0% 6 mph 73 % 1027 mb 0 mm/h
Tomorrow 6:00 pm
weather icon
6° | 6°°C 0 mm 0% 6 mph 73 % 1027 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
4° | 4°°C 0 mm 0% 6 mph 82 % 1026 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€97,848.52
-3.28%
Ethereum(ETH)
€3,190.45
2.27%
XRP(XRP)
€2.90
-3.48%
Tether(USDT)
€0.96
-0.06%
Solana(SOL)
€220.87
-4.03%
USDC(USDC)
€0.96
0.00%
Dogecoin(DOGE)
€0.313779
-1.82%
Shiba Inu(SHIB)
€0.000018
0.23%
Pepe(PEPE)
€0.000013
8.08%
Scroll to Top