HomeSecurityPolice seize infostealer operation Redline and Meta

Police seize infostealer operation Redline and Meta

The Dutch National Police have seized the network infrastructure for the Redline and Meta infostealer malware operations, with “Operation Magnus”, warning cybercriminals that their data is now in the hands of law enforcement authorities.

Meta info stealer

See also: WordPress sites hacked: Fake plugins promote info-stealer malware

Operation Magnus was announced on a dedicated website that revealed the shutdown of Redline and Meta infostealer operations, stating that legal actions are currently underway based on the seized data.

Redline and Meta are both infostealers, a type of malware that steals stored information from browsers on an infected device, including credentials, authentication cookies, browsing history, sensitive documents, SSH keys, and cryptocurrency wallets.

This data is then sold by threat actors or used to fuel massive breaches , leading to data theft, ransomware , and cyberespionage.

Politie says they managed to disrupt the Redline and Meta infostealer operation, with the help of international law enforcement partners, including the FBI, NCIS, the US Department of Justice, Eurojust, the NCA, and police forces in Portugal and Belgium.

See also: Internet Archive hacked again via stolen authentication tokens

The agencies released a video announcing the "final update" for Redline and Meta users, warning that they now have their account credentials, IP addresses, activity timestamps, registration details, and more.

Police seize infostealer operation Redline and Meta

This makes it clear that researchers have evidence that can be used to identify cybercriminals who used the malware, so arrests and prosecutions are likely to be announced in the future.

Additionally, authorities claimed to have access to the source code, including license servers, REST-API services, panels, theft binaries, and Telegram bots, for both malware.

As they stated in the video, both Meta and Redline shared the same infrastructure, so it is possible that the same creators/operators are behind both infostealers.

Malware researcher g0njxa told BleepingComputer that both Redline and Meta were sold through bots on Telegram, which have now been deleted.

More information about the operation, the seized infrastructure and possible arrests is expected to be made public soon.

See also: Cyprus thwarted cyberattack on government portal

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

An infostealer is a type of malware designed to target and capture sensitive information from computer . Typically, infostealers, such as Redline and Meta, aim to collect data such as login credentials, banking information, and other personal information by exploiting security vulnerabilities. These programs can operate silently, often without the user’s knowledge, and may transmit the collected information back to a remote server controlled by cybercriminals. Protecting against infotealers requires strong cybersecurity measures, such as up-to-date antivirus software, firewalls, and constant monitoring of network activity to detect any suspicious behavior.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS