Seventeen months after the RedLine infostealer was dismantled by international law enforcement, a second defendant appeared in U.S. federal court — this time extradited from Armenia.

Armenian national Hambardzum Minasyan appeared in federal court in Austin after being extradited to the United States to face charges related to his alleged role in the RedLine infostealer attacks. The Department of Justice’s Bureau of International Affairs secured Minasyan’s arrest and extradition on March 23, 2026, with significant assistance from Eurojust’s ICHIP, based in The Hague.
Minasyan faces three counts: conspiracy to commit fraud-device access, conspiracy to violate the Computer Abuse Prevention Act , and conspiracy to commit money laundering . If convicted, he faces up to 10 years in prison for the device access charge and up to 20 years for the other two charges.
RedLine infostealer
The RedLine infostealer was one of the most destructive malware of its kind. An infostealer is malicious software designed to steal credentials, browser cookies, saved passwords, financial data , and cryptocurrency wallet information from an infected device. It then transmits this data to attackers — often within seconds, with no apparent sign of a breach.
See also: GlassWorm malware hides RAT in Chrome extension
The indictment alleges that Minasyan and his associates maintained digital infrastructure, including command and control servers and administrative panels, to deploy the malware and collect payments from associates who used RedLine against victims.
Minasyan, specifically, registered two virtual private servers and two web domains to support the RedLine scam, created repositories on an online file-sharing website to distribute RedLine to collaborators, and registered a cryptocurrency account in November 2021 to receive payments.

Malware-as-a-Service Approach
RedLine operated under a Malware-as-a-Service. This is a criminal franchise structure where the core developers build and maintain the malware platform and then license it to affiliates who run their own infection campaigns in exchange for a fee. Affiliates distributed RedLine to victims using malicious advertising, phishing emails, fake software downloads, and malicious software loading, with various tricks — including COVID-19 bait and Windows updates.
RedLine and its derivative Meta infostealer could also allow cybercriminals to bypass multi-factor authentication by stealing authentication cookies and session tokens. Multi-factor authentication is a layer of security that requires users to verify their identity through a second method in addition to a password. Stealing session cookies allows attackers to impersonate an already authenticated user and render this protection useless.
See also: DarkSword exploit leaked on GitHub
The Lapsus$ threat group used RedLine to obtain passwords and cookies from an employee account at a major technology company and then used that access to obtain and leak restricted source code . RedLine also infected hundreds of systems belonging to U.S. Department of Defense personnel, and authorities have reported that the malware is linked to millions of victims worldwide.
Minasyan is the second person to be charged in connection with Operation Magnus, the joint international disarmament operation announced in October 2024.
Operation Magnus — a Europol- supported Joint Cybercrime Task Force operation — resulted in the seizure of three servers running the malware , the seizure of communication channels and Telegram accounts used by the operators, and the recovery of a database of thousands of RedLine and Meta customers.

This customer database gave researchers a road map for further prosecutions that continue to yield results.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: VoidStealer malware steals passwords – Chrome ABE bypass
The first defendant, Russian national Maxim Rudometov, was identified as the developer and administrator of RedLine and was indicted in the Western District of Texas in October 2024. Rudometov, believed to reside in Krasnodar, Russia, is not expected to face extradition due to his location.
extradition from Armenia, by contrast, demonstrates the value of maintaining extradition treaty relationships and Eurojust cooperation frameworks, which can reach defendants outside jurisdictions beyond the reach of the U.S.
The investigation is a joint effort by the Force Cybercrime Task FBI's in Austin, which includes the Navy's Criminal Investigation Service, the IRS Criminal Investigation Service, the Department of Defense's Office of Inspector General, and the Army's Criminal Investigations Directorate.
