Dutch Police Disrupt Main Data Stealers RedLine and MetaStealer in Operation Magnus

Oct 29, 2024Ravie LakshmananCybercrime / Malware

The Dutch Nationwide Police, together with worldwide companions, have introduced the disruption of the infrastructure powering two info stealers tracked as RedLine and MetaStealer.

The takedown, which happened on October 28, 2024, is the results of a world regulation enforcement activity pressure codenamed Operation Magnus that concerned authorities from the U.S., the U.Ok., Belgium, Portugal, and Australia.

Cybersecurity

Eurojust, in a assertion revealed immediately, stated the operation led to the shut down of three servers within the Netherlands and the confiscation of two domains. In complete, over 1,200 servers in dozens of nations are estimated to have been used to run the malware.

As a part of the efforts, one administrator has been charged by the U.S. authorities and two individuals have been arrested by the Belgian police, the Politie stated, including one in every of them has since been launched, whereas the opposite stays in custody.

The U.S. Division of Justice (DoJ) has charged Maxim Rudometov, one of many RedLine Stealer’s builders and directors, with entry gadget fraud, conspiracy to commit laptop intrusion, and cash laundering. If convicted, he faces a most penalty of 35 years in jail.

“Rudometov regularly accessed and managed the infrastructure of RedLine Infostealer, was associated with various cryptocurrency accounts used to receive and launder payments and was in possession of RedLine malware,” the DoJ stated.

Investigation into the technical infrastructure of the knowledge stealers started a 12 months in the past primarily based on a tip from cybersecurity firm ESET that the servers are situated within the Netherlands.

Among the many information seized included usernames, passwords, IP addresses, timestamps, registration dates, and the supply code of each the stealer malware. In tandem, a number of Telegram accounts related to the stealer malware have been taken offline. Additional investigation into their clients is ongoing.

“The infostealers RedLine and MetaStealer were offered to customers via these groups,” Dutch regulation enforcement officers stated. “Until recently, Telegram was a service where criminals felt untouchable and anonymous. This action has shown that this is no longer the case.”

It is price noting that the MetaStealer goal as a part of Operation Magnus is completely different from the MetaStealer malware that is recognized to focus on macOS gadgets.

Cybersecurity

Info stealers akin to RedLine and MetaStealer are essential cogs within the cybercrime wheel, permitting menace actors to siphon credentials and different delicate info that might then be bought off to different menace actors for follow-on assaults like ransomware.

Stealers are usually distributed underneath a malware-as-a-service (MaaS) mannequin, which means the core builders lease entry to the instruments to different cybercriminals both on a subscription foundation or for a lifetime license.

Discovered this text fascinating? Comply with us on Twitter and LinkedIn to learn extra unique content material we put up.

Recent articles