Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

MetaStealer

51
Global rank
40 infographic chevron month
Month rank
42 infographic chevron week
Week rank
0
IOCs

MetaStealer is an info-stealing malware primarily targeting sensitive data like login credentials, payment details, and browser history. It typically infects systems via phishing emails or malicious downloads and can exfiltrate data to a command and control (C2) server. MetaStealer is known for its stealthy techniques, including evasion and persistence mechanisms, which make it difficult to detect. This malware has been actively used in various cyberattacks, particularly for financial theft and credential harvesting from individuals and organizations.

Stealer
Type
Unknown
Origin
1 March, 2022
First seen
9 April, 2026
Last seen

How to analyze MetaStealer with ANY.RUN

Type
Unknown
Origin
1 March, 2022
First seen
9 April, 2026
Last seen

IOCs

IP addresses
138.201.198.8
81.161.229.143
82.115.223.13
45.15.157.1
37.220.87.13
5.42.65.101
89.22.234.180
45.15.156.13
77.73.134.70
162.55.188.117
37.220.87.8
212.113.116.143
185.106.93.153
176.123.9.85
185.161.248.152
185.161.248.143
78.153.130.209
185.161.248.72
165.22.108.237
77.91.124.111
Domains
ns.edahua.top
marduk.top
popshues.top
fhgerbugjreqnhfegrb.top
trenity.top
musonare.top
apiamad.tuktuk.ug
Last Seen at
Last Seen at

Recent blog posts

post image
Building Phishing Detection That Works: 3 Ste...
watchers 456
comments 0
post image
ClickFix Meets AI: A Multi-Platform Attack Ta...
watchers 2547
comments 0
post image
From Reactive to Proactive: 5 Steps to SOC Ma...
watchers 4757
comments 0

What is MetaStealer malware?

MetaStealer is an information-stealing malware first observed in 2022. Initially announced on underground forums, MetaStealer is available as a malware-as-a-service (MaaS) for a subscription price of $125 per month or $1,000 for lifetime use.

Based on the RedLine stealer codebase, it includes several improvements, making it a more effective tool for credential theft and data exfiltration.

This malware has been distributed mainly through malspam campaigns, often using phishing emails to drop the malicious payload into the victim's machine.

MetaStealer has been observed in malvertising campaigns and cracked software distributed through compromised YouTube accounts. Its ability to steal login credentials, cryptocurrency wallet information, and browser-stored data has made it a popular choice among cybercriminals.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

MetaStealer malware technical details

The primary functionality of MetaStealer malware is to exfiltrate sensitive data from infected systems. Its key features include:

  • Steals login credentials, browser data, and cryptocurrency wallet info.
  • Sends stolen data to a remote command and control server.
  • Targets web browsers and email clients for stored credentials.
  • Modifies registry keys to reinfect systems after reboot.
  • Uses obfuscation to avoid detection by antivirus tools.
  • Spreads via phishing emails, malvertising, and cracked software.
  • Focuses on exploiting browsers to steal saved login info.
  • Available for subscription, making it widely accessible to attackers.
  • Can install additional malware on infected systems.

Once executed, MetaStealer is capable of establishing persistence on the infected system by modifying registry keys, making sure that it can reinfect the machine after a reboot. This persistence mechanism helps attackers maintain prolonged access to compromised systems.

MetaStealer's focus on browser exploitation is particularly dangerous, as it targets saved login credentials, autofill data, cookies, and other session information stored in web browsers. This gives attackers the ability to access a wide range of online accounts, from social media to financial services, without needing direct interaction from the victim.

MetaStealer malware execution process

To see how MetaStealer operates, let’s upload its sample to the ANY.RUN sandbox.

Metastealer process graph in ANY.RUN Metastealer process graph shown in ANY.RUN sandbox

Upon execution, MetaStealer may retrieve information about the operating system using winver.exe. It then duplicates itself, creating a copy that is placed in the local application data directory (%localappdata%\Microsoft\windows) and executed to maintain persistence.

To evade detection by Windows Defender, the malware may employ a PowerShell command to add exclusions for certain file types, allowing it to execute without triggering antivirus alerts. This command specifically targets executable files, facilitating the malware's operation without hindrance.

MetaStealer then collects extensive system details by executing systeminfo.exe.

Following this, it focuses on extracting sensitive information from installed web browsers, such as autofill data, cookies, and login credentials. This information is crucial for attackers as it can provide access to various online accounts and services.

After gathering the necessary information, MetaStealer prepares to send the stolen data back to the attackers, typically by establishing a connection to remote servers where the collected information is transmitted.

The exact mechanisms for exfiltration can vary but often involve HTTP POST requests to predefined command and control (C&C) servers.

In our example task, MetaStealer injects itself into the RegAsm system process to evade process-based defenses and possibly elevate privileges. The injected process attempted to connect to the C2 server, triggering a Suricata rule.

In some cases, the malware may arrive on the system alongside legitimate software, masquerading to avoid suspicion.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

MetaStealer malware distribution methods

MetaStealer is distributed through various methods, with attackers using different tactics to target victims. Some of the key distribution methods include:

  • Phishing emails with malicious attachments: One of the most common methods, MetaStealer is often delivered via phishing emails containing malicious attachments such as Word documents (.doc/.docx) or compressed files (.zip/.rar). These files may contain macros or embedded executables that launch the malware.
  • Malicious links: Emails can also include links that redirect the user to a malicious site where the malware is downloaded, disguised as legitimate software or documents.
  • Malvertising: Attackers sometimes use malicious online advertisements that lead to infected websites. These websites can either directly download MetaStealer or prompt users to install disguised malicious software.
  • Cracked software: MetaStealer has been found bundled with cracked or pirated software. Users who download software from untrusted sources may inadvertently install the malware along with what they believe to be legitimate applications.
  • Fake websites: Attackers may create fake websites that mimic legitimate ones, prompting users to download infected files or software updates that actually deliver MetaStealer.

Gathering threat intelligence on MetaStealer malware

To collect up-to-date intelligence on MetaStealer, use Threat Intelligence Lookup.

This service provides access to a large database filled with insights from millions of malware analysis sessions conducted in the ANY.RUN sandbox. With more than 40 customizable search parameters, you can find relevant data on threats including elements like IPs, domains, file names, and process artifacts.

Metastealer lookup search in ANY.RUN Search results for Metastealer in Threat Intelligence Lookup

For example, to gather intelligence on MetaStealer, you can search directly for its threat name or use a related artifact. By submitting a query like threatName:"MetaStealer", TI Lookup will bring up all associated samples and sandbox results relevant to this malware.

Get a 14-day free trial of Threat Intelligence Lookup along with the ANY.RUN sandbox

Conclusion

MetaStealer poses a significant threat due to its ability to steal credentials and spread through various distribution methods. It’s crucial to proactively analyze suspicious files and URLs to protect against this and similar malware.

ANY.RUN offers real-time threat analysis, letting users investigate suspicious files, track malware behavior, and collect actionable intelligence to improve security defenses.

Sign up for a free ANY.RUN account today and start analyzing emerging threats with no limits!

HAVE A LOOK AT

Cerber screenshot
Cerber
cerber
Cerber is a Ransomware-as-a-Service (RaaS) that appeared in 2016, spread quickly and has been evolving since. It became well-known for its file encryption, offline capabilities, and sophisticated evasion techniques. It primarily targets enterprises, financial institutions, and government entities, encrypting their data and demanding ransom payments in Bitcoin. It also targets everyday users encrypting personal files (photos, documents) with the risk of their permanent loss.
Read More
SSLoad screenshot
SSLoad
ssload
SSLoad is a malicious loader or downloader that is used to infiltrate target systems through phishing emails, perform reconnaissance and transmit it back to its operators delivering malicious payloads. To avoid detection, SSLoad employs various encryption methods and delivery techniques highlighting its versatile nature and complexity. It is believed to be a part of Malware-as-a-Service (MaaS) operation given its diverse delivery methods and implemented techniques.
Read More
Backdoor screenshot
Backdoor
backdoor
A backdoor is a type of cybersecurity threat that allows attackers to secretly compromise a system and conduct malicious activities, such as stealing data and modifying files. Backdoors can be difficult to detect, as they often use legitimate system applications to evade defense mechanisms. Threat actors often utilize special malware, such as PlugX, to establish backdoors on target devices.
Read More
Prometei screenshot
Prometei
prometei
Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.
Read More
PureCrypter screenshot
PureCrypter
purecrypter
First identified in March 2021, PureCrypter is a .NET-based loader that employs obfuscation techniques, such as SmartAssembly, to evade detection. It has been used to distribute malware families including AgentTesla, RedLine Stealer, and SnakeKeylogger. The malware is typically delivered through phishing campaigns and malicious downloads, often masquerading as legitimate files with extensions like .mp4 or .pdf. PureCrypter utilizes encryption and compression to conceal its payloads and can inject malicious code into legitimate processes to maintain persistence on the infected system.
Read More
DarkComet screenshot
DarkComet
darkcomet rat darkcomet rat
DarkComet RAT is a malicious program designed to remotely control or administer a victim's computer, steal private data and spy on the victim.
Read More