# Meta vs Redline Stealer

**URL:** <https://community.emergingthreats.net/t/meta-vs-redline-stealer/1141>\
**Category:** Rule Signatures\
**Created:** [November 21, 2023, 11:51am UTC](https://community.emergingthreats.net/t/meta-vs-redline-stealer/1141 "2023-11-21T11:51:30Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![g0njxa](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/g0njxa/32/364_2.png) [@g0njxa](https://community.emergingthreats.net/u/g0njxa)\
**Post date:** [November 21, 2023, 11:51am UTC](https://community.emergingthreats.net/t/meta-vs-redline-stealer/1141/1 "2023-11-21T11:51:30Z")

</div>

Meta Stealer has been around since 2022 and has been used very frequently by TA in the stealers market. Somehow and because of C2 traffic similarities on Redline and Meta builds, this second has been “forget” by malware analysts and hunters, under the Redline name.

Recently, Threat Intelligence Researcher @AnFam17 has made an amazing report on this stealer:  
[MetaStealer - Redline’s Doppelgänger (russianpanda.com)](https://russianpanda.com/2023/11/20/MetaStealer-Redline's-Doppelganger/)  
So we finally can start digging into Meta stealer and its detection.

Meta should be considered a malware from the same family as Redline, that actually has nothing to do with the outdated references on [MetaStealer (Malware Family) (fraunhofer.de)](https://malpedia.caad.fkie.fraunhofer.de/details/win.metastealer)  
and outdated ETPRO MALWARE Win32/MetaStealer Related Activity (GET) sid: 2851362  
ETPRO MALWARE Win32/MetaStealer Related Activity (POST) sid: 2851363

Here is some additional Redline (PID 2580) vs Meta (PID 2712) detonations:  
[Analysis test123.rar (MD5: C6375702EA8D3E9F14A97BE68240EE65) Malicious activity - Interactive analysis ANY.RUN](https://app.any.run/tasks/5ce0ab5b-4240-4701-87ed-0b88cf9577a7/)

What are the thoughts on ET community on bringing back detection to Meta Stealer updating the rules from 2022? Or what it seems more reasonable, to add some dual detection on both Redline and Meta samples but anything additional to help identifying Meta builds.

I say this because there’s currently some Meta builds that doesn’t have any rule detection, than a ET INFO Microsoft net.tcp Connection Initialization Activity. For example:  
[Analysis https://cdn.discordapp.com/attachments/1175696087399546890/1175697604072443964/Installer.zip?ex=656c2cb8&is=6559b7b8&hm=a90808c4f39ddbcf46113c3b3464f9d3a65d98dd80bd8706bea3852333820753& Malicious activity - Interactive analysis ANY.RUN](https://app.any.run/tasks/340c4c86-f202-4ee3-a98d-316ec7ef7eb9/)

---

<div class="post-metadata">

**Author:** ![jtaylor](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jtaylor/32/12_2.png) [@jtaylor](https://community.emergingthreats.net/u/jtaylor)\
**Post date:** [November 22, 2023, 7:56pm UTC](https://community.emergingthreats.net/t/meta-vs-redline-stealer/1141/2 "2023-11-22T19:56:46Z")

</div>

Thank you for the heads up on this. We will have an additional signature out today specifcally for MetaStealer. I am still going through MetaStealer samples so more sigs may follow. Thank you again for the updates around these malwares!

JT

---

<div class="post-metadata">

**Author:** ![jtaylor](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jtaylor/32/12_2.png) [@jtaylor](https://community.emergingthreats.net/u/jtaylor)\
**Post date:** [November 22, 2023, 9:15pm UTC](https://community.emergingthreats.net/t/meta-vs-redline-stealer/1141/3 "2023-11-22T21:15:32Z")

</div>

2049282 - ET MALWARE MetaStealer Activity (Response)

Went out in todays release, we will be going through the redline sigs and updating to indicate metastealer where appropriate as well. Again, thank you for bringing this up!

JT

---

<div class="post-metadata">

**Author:** ![g0njxa](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/g0njxa/32/364_2.png) [@g0njxa](https://community.emergingthreats.net/u/g0njxa)\
**Post date:** [January 6, 2024, 5:56pm UTC](https://community.emergingthreats.net/t/meta-vs-redline-stealer/1141/4 "2024-01-06T17:56:06Z")

</div>

Meta Stealer experienced an update at the first days of December, upgrading its version to v4.

Here’s the analysis provided by @Anfam17 aka RussianPanda

[MetaStealer Part 2, Google Cookie Refresher Madness and Stealer Drama (russianpanda.com)](https://russianpanda.com/2023/12/28/MetaStealer-Part-2/)

Since rules has been applied to the v3 version, this new variants are still detected as Redline but Meta is not contemplated in any way

Some recent example:  
[Analysis file.exe (MD5: 510B0F5662E6A9153FFE3FA6F1CC7B5C) Malicious activity - Interactive analysis ANY.RUN](https://app.any.run/tasks/2a15a217-f90e-4596-8d5e-8f7fc363ad83)

Thank you

---

<div class="post-metadata">

**Author:** ![jtaylor](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jtaylor/32/12_2.png) [@jtaylor](https://community.emergingthreats.net/u/jtaylor)\
**Post date:** [January 9, 2024, 3:10pm UTC](https://community.emergingthreats.net/t/meta-vs-redline-stealer/1141/5 "2024-01-09T15:10:54Z")

</div>

Thanks! We will take a look and make any updates for todays release.

JT
