Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

MetaStealer

70
Global rank
91 infographic chevron month
Month rank
107 infographic chevron week
Week rank
0
IOCs

MetaStealer is an info-stealing malware primarily targeting sensitive data like login credentials, payment details, and browser history. It typically infects systems via phishing emails or malicious downloads and can exfiltrate data to a command and control (C2) server. MetaStealer is known for its stealthy techniques, including evasion and persistence mechanisms, which make it difficult to detect. This malware has been actively used in various cyberattacks, particularly for financial theft and credential harvesting from individuals and organizations.

Stealer
Type
Unknown
Origin
1 March, 2022
First seen
25 August, 2026
Last seen

How to analyze MetaStealer with ANY.RUN

Type
Unknown
Origin
1 March, 2022
First seen
25 August, 2026
Last seen

IOCs

IP addresses
23.59.18.102
54.192.35.16
150.171.109.193
23.11.41.157
23.52.181.212
40.126.31.1
2.23.246.9
151.101.1.91
18.66.107.176
48.192.1.64
151.101.65.91
150.171.109.194
104.18.86.42
2.16.204.153
18.64.181.100
142.251.13.100
150.171.22.17
20.165.94.54
142.250.154.119
172.217.208.95
Hashes
3a0285c8233ef0324b269f7291094e19fd9b77259f9419861ad796f7e9c979f3
4f5d849bdf4a5eeeb5da8836589e064e31c8e94129d4e55b1c69a6f98fb9f9ea
02da51970f2808353c5d402b60067ecbca43e3f84dbf782c1ad1a2781320e56f
8be4a2270f8b2bea40f33f79869fdcca34e07bb764e63b81ded49d90d2b720dd
967dddbfe7f1ceb933b5875d65c59cdb835bb063f287a361e8b35dd814a9b14d
b755d0b55a465d07c9dd3fc11822487d1e649b684aef91a4ce9b935b416a01b9
b5d20736f84f335ef4c918a5ba41c3a0d7189397c71b166ccc6c342427a94ece
04cae3c7b208fc55b25763913d0bbdc99232942086efdf705f2a27764be6f5ee
66409f670315afe8610f17a4d3a1ee52d72b6a46c544cec97544e8385f90ad74
4b8940bec0467d78e75c7eaaf08b998c9cfbc4297e06490b1bee1267a4649c04
4d97caeee07cfd354e2f5210ad1522c948bdcfc520fe8bde27652cda92f28241
d474865a5e5c2f9d039c0f7a017e9a5e23a159cf6f534e879e979c61085fa1f9
cd8b03f62a20d47fc5c9a495615b350e4da7eabfff34b8e112afec63bab1cbec
c1de5d01d11cfe466b819af52ba381f217573c889781c60be82eb285e9fa8908
a136c0e17264c40873534669af5f78e7e17e70f8661046c32599c6615cad80cf
57a03ea6c0480797d923c72ece7e6e5d3b0b34299bfb879f67e519c9b6cd4fcc
056e734fd9ef5bbe213a5fccfc32b23f71f7f6cf7b792fa8e614d1c968a2210e
3564b25b24569b8d8a0128f2f4bddec89c0b8986da7542d9c64aac730360a600
4d34160482a2fe82b27d396eac3c32b5e9aed7e774e8a60dbe787bd066988944
2d209c2b823e350c1f1661f87a3a013804302477afe56877f94adbafe7a2e06d
Domains
www.bing.com
slscr.update.microsoft.com
fonts.googleapis.com
edge.microsoft.com
youtube.com
api.getfiddler.com
cdnjs.cloudflare.com
settings-win.data.microsoft.com
sv.symcb.com
ts-crl.ws.symantec.com
rr4---sn-ixh7rn76.googlevideo.com
clients2.googleusercontent.com
go.microsoft.com
d585tldpucybw.cloudfront.net
api.edgeoffer.microsoft.com
location.services.mozilla.com
self.events.data.microsoft.com
ocsp.thawte.com
config.edge.skype.com
www.google.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://copilot.microsoft.com/c/api/user/eligibility
https://api.getfiddler.com/r/?fiddler2firstrun
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:3ctp62-jldtm3wxonyuacxr_u9iksgx-xwlac5kw2mu&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://www.telerik.com/download/fiddler/first-run
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://www.telerik.com/webresource.axd?d=dzhrpql5urxarfhatrmzfpt6hpdyvmvwc29nqzntmgysoltubafjejmhfet-tzvek6ozukcflv6buazsf-hybiteasuohqp_tgcrtdu8m-w3kcownlktxcr0j5idbgmxgzpr0epgjcz5_ebwd3lcl6thd1nxnha5rjpekjowo8zlicp89mzwq717vgrigsdw0&t=639198239780000000
https://www.telerik.com/webresource.axd?d=htqyxelcu6mzspcvcvk_bnblutvft4ynhixmh-5hvnkgqbyrihbbxow-wlawts4fh-uezcj3u3bxogxta9ietv0ygoerorfnwefm4ee4gkmjgfouuad27x8_kp6mxfbuoycxugsypjkcrpiaxeuklnlzk7m8ff_sisbducjragc7qhymaatrttzcqgfpihxxug-jfb_e0_0l8itii7oyj_qlieujvha-wpkcceskwp41&t=639198240000000000
https://www.telerik.com/abtesting/active-ab-tests.js
https://www.telerik.com/webresource.axd?d=wnb2ojhyopty-dcfa4b2kioosflbl-swancjatkks0y4muk1q8bvuocionpbok2pofwwtrm6ijfmcbpw3lzin2oj88aguuszvnzohppne35mlqtpglfhujn4zcfigrff9ipn2emxbosmkkprew3n_1wbzaz04z0cfxwa0cwbigyqkuorq1zse-gjutqbu6qejnwi34avhflpj_thcnbw_xf384gh9o7prdekcvs3abw1&t=639198240780000000
https://www.telerik.com/webresource.axd?d=njxtqr2bqtw1rewxxlkhphr-2awqigc1t4afxfkrlq9hya2sd15bgrdgiyxv5oymd7lm20nxinlfnq7rubkudq2rdnhnt0g9zqyw8hltmfjckkorrcw5dv0tbfxspvdhjp04y9sytz7mnzs4jpk7kvcqyvwcxk_9ll20ml6ljlzfls7riwznqaggxv0sk0sxw5161bhghvkqb9ucayn9kq57pv9u23le6pml2fneac01&t=639198240780000000
https://cdn.cookielaw.org/consent/3dfce4f2-dab6-4128-9f33-df7e0597da82/otsdkstub.js
https://cdnjs.cloudflare.com/ajax/libs/jquery/3.7.1/jquery.min.js
https://cdnjs.cloudflare.com/ajax/libs/jquery-migrate/3.4.1/jquery-migrate.min.js
https://dtzbdy9anri2p.cloudfront.net/cache/56eb6092ec76515afdab8d71e3f978f10325d00b/telerik/css/style.css
https://dtzbdy9anri2p.cloudfront.net/cache/4b1e430a19e2d5ad42a202316a065ddb8138af75/telerik/js/dist/polyfills.min.js
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 4136
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 10033
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 12522
comments 0

What is MetaStealer malware?

MetaStealer is an information-stealing malware first observed in 2022. Initially announced on underground forums, MetaStealer is available as a malware-as-a-service (MaaS) for a subscription price of $125 per month or $1,000 for lifetime use.

Based on the RedLine stealer codebase, it includes several improvements, making it a more effective tool for credential theft and data exfiltration.

This malware has been distributed mainly through malspam campaigns, often using phishing emails to drop the malicious payload into the victim's machine.

MetaStealer has been observed in malvertising campaigns and cracked software distributed through compromised YouTube accounts. Its ability to steal login credentials, cryptocurrency wallet information, and browser-stored data has made it a popular choice among cybercriminals.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

MetaStealer malware technical details

The primary functionality of MetaStealer malware is to exfiltrate sensitive data from infected systems. Its key features include:

  • Steals login credentials, browser data, and cryptocurrency wallet info.
  • Sends stolen data to a remote command and control server.
  • Targets web browsers and email clients for stored credentials.
  • Modifies registry keys to reinfect systems after reboot.
  • Uses obfuscation to avoid detection by antivirus tools.
  • Spreads via phishing emails, malvertising, and cracked software.
  • Focuses on exploiting browsers to steal saved login info.
  • Available for subscription, making it widely accessible to attackers.
  • Can install additional malware on infected systems.

Once executed, MetaStealer is capable of establishing persistence on the infected system by modifying registry keys, making sure that it can reinfect the machine after a reboot. This persistence mechanism helps attackers maintain prolonged access to compromised systems.

MetaStealer's focus on browser exploitation is particularly dangerous, as it targets saved login credentials, autofill data, cookies, and other session information stored in web browsers. This gives attackers the ability to access a wide range of online accounts, from social media to financial services, without needing direct interaction from the victim.

MetaStealer malware execution process

To see how MetaStealer operates, let’s upload its sample to the ANY.RUN sandbox.

Metastealer process graph in ANY.RUN Metastealer process graph shown in ANY.RUN sandbox

Upon execution, MetaStealer may retrieve information about the operating system using winver.exe. It then duplicates itself, creating a copy that is placed in the local application data directory (%localappdata%\Microsoft\windows) and executed to maintain persistence.

To evade detection by Windows Defender, the malware may employ a PowerShell command to add exclusions for certain file types, allowing it to execute without triggering antivirus alerts. This command specifically targets executable files, facilitating the malware's operation without hindrance.

MetaStealer then collects extensive system details by executing systeminfo.exe.

Following this, it focuses on extracting sensitive information from installed web browsers, such as autofill data, cookies, and login credentials. This information is crucial for attackers as it can provide access to various online accounts and services.

After gathering the necessary information, MetaStealer prepares to send the stolen data back to the attackers, typically by establishing a connection to remote servers where the collected information is transmitted.

The exact mechanisms for exfiltration can vary but often involve HTTP POST requests to predefined command and control (C&C) servers.

In our example task, MetaStealer injects itself into the RegAsm system process to evade process-based defenses and possibly elevate privileges. The injected process attempted to connect to the C2 server, triggering a Suricata rule.

In some cases, the malware may arrive on the system alongside legitimate software, masquerading to avoid suspicion.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

MetaStealer malware distribution methods

MetaStealer is distributed through various methods, with attackers using different tactics to target victims. Some of the key distribution methods include:

  • Phishing emails with malicious attachments: One of the most common methods, MetaStealer is often delivered via phishing emails containing malicious attachments such as Word documents (.doc/.docx) or compressed files (.zip/.rar). These files may contain macros or embedded executables that launch the malware.
  • Malicious links: Emails can also include links that redirect the user to a malicious site where the malware is downloaded, disguised as legitimate software or documents.
  • Malvertising: Attackers sometimes use malicious online advertisements that lead to infected websites. These websites can either directly download MetaStealer or prompt users to install disguised malicious software.
  • Cracked software: MetaStealer has been found bundled with cracked or pirated software. Users who download software from untrusted sources may inadvertently install the malware along with what they believe to be legitimate applications.
  • Fake websites: Attackers may create fake websites that mimic legitimate ones, prompting users to download infected files or software updates that actually deliver MetaStealer.

Gathering threat intelligence on MetaStealer malware

To collect up-to-date intelligence on MetaStealer, use Threat Intelligence Lookup.

This service provides access to a large database filled with insights from millions of malware analysis sessions conducted in the ANY.RUN sandbox. With more than 40 customizable search parameters, you can find relevant data on threats including elements like IPs, domains, file names, and process artifacts.

Metastealer lookup search in ANY.RUN Search results for Metastealer in Threat Intelligence Lookup

For example, to gather intelligence on MetaStealer, you can search directly for its threat name or use a related artifact. By submitting a query like threatName:"MetaStealer", TI Lookup will bring up all associated samples and sandbox results relevant to this malware.

Get a 14-day free trial of Threat Intelligence Lookup along with the ANY.RUN sandbox

Conclusion

MetaStealer poses a significant threat due to its ability to steal credentials and spread through various distribution methods. It’s crucial to proactively analyze suspicious files and URLs to protect against this and similar malware.

ANY.RUN offers real-time threat analysis, letting users investigate suspicious files, track malware behavior, and collect actionable intelligence to improve security defenses.

Sign up for a free ANY.RUN account today and start analyzing emerging threats with no limits!

HAVE A LOOK AT

ValleyRAT screenshot
ValleyRAT
valleyrat
ValleyRAT is a classic remote access trojan first documented in 2023, targeting mainly Windows systems. It is used by threat actors to gain persistent access to infected devices, steal data, and control compromised machines. ValleyRAT is notable for its relatively advanced evasion techniques and its connections to a prominent Chinese APT group.
Read More
Razr screenshot
Razr
razr
Razr is a destructive ransomware that infiltrates systems to encrypt files, rendering them inaccessible to users. It appends the ".razr" extension to the encrypted files and drops a ransom note, typically named "README.txt," instructing victims on how to pay the ransom to obtain the decryption key. The malware often spreads through phishing emails with malicious attachments or by exploiting vulnerabilities in software and operating systems. Razr employs strong encryption algorithms, making it challenging to decrypt files without the attackers' key.
Read More
RondoDox screenshot
RondoDox
rondodox
RondoDox is an emerging Linux-based botnet malware that exploits dozens of known vulnerabilities in internet-facing devices like routers, DVRs, and web servers to build massive networks for DDoS attacks, cryptomining, and data exfiltration. First spotted in mid-2025, its "exploit shotgun" tactic (firing multiple payloads at once) has made it a rapid escalator in the IoT threat landscape, compromising unpatched edge devices worldwide.
Read More
DragonForce screenshot
DragonForce
dragonforce
DragonForce is a ransomware strain operating under the Ransomware-as-a-Service (RaaS) model. First reported in December 2023, it encrypts files with ChaCha8, renames them with random strings, and appends “.dragonforce_encrypted.” By disabling backups, wiping recovery, and spreading across SMB shares, DragonForce maximizes damage and pressures victims into multimillion-dollar ransom negotiations. It has targeted manufacturing, construction, IT, healthcare, and retail sectors worldwide, making it a severe threat to modern enterprises.
Read More
DarkComet screenshot
DarkComet
darkcomet rat darkcomet rat
DarkComet RAT is a malicious program designed to remotely control or administer a victim's computer, steal private data and spy on the victim.
Read More
StrelaStealer screenshot
StrelaStealer
strela
StrelaStealer is a malware that targets email clients to steal login credentials, sending them back to the attacker’s command-and-control server. Since its emergence in 2022, it has been involved in numerous large-scale email campaigns, primarily affecting organizations in the EU and U.S. The malware’s tactics continue to evolve, with attackers frequently changing attachment file formats and updating the DLL payload to evade detection.
Read More