Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

MetaStealer

99
Global rank
98 infographic chevron month
Month rank
80 infographic chevron week
Week rank

MetaStealer is an info-stealing malware primarily targeting sensitive data like login credentials, payment details, and browser history. It typically infects systems via phishing emails or malicious downloads and can exfiltrate data to a command and control (C2) server. MetaStealer is known for its stealthy techniques, including evasion and persistence mechanisms, which make it difficult to detect. This malware has been actively used in various cyberattacks, particularly for financial theft and credential harvesting from individuals and organizations.

Stealer
Type
Unknown
Origin
1 March, 2022
First seen
7 October, 2026
Last seen

How to analyze MetaStealer with ANY.RUN

Type
Unknown
Origin
1 March, 2022
First seen
7 October, 2026
Last seen

IOCs

IP addresses
40.126.32.133
48.192.1.65
23.11.41.157
23.52.181.40
74.179.77.204
23.207.210.139
48.209.133.15
213.155.159.188
104.126.37.163
172.211.123.250
104.40.149.189
104.18.21.213
23.216.77.19
104.126.37.144
135.232.92.97
204.79.197.203
23.52.181.212
48.209.138.168
194.26.135.119
23.52.181.141
Hashes
cac263e0e90a4087446a290055257b1c39f17e11f065598cb2286df4332c7696
b8e90e20edf110aaaaea54fbc8533872831777be5589e380cfdd17e1f93147b5
226b778604236931b4ae45f6f272586c884a11517444a34bf45cd5cae49be62e
a40c94eb33f8841c79e9f6958433affd517f97b4570f731666af572e63178bb7
ecb5c22e6c2423caf07aebe69f4faf22450164eee9587b64ef45a2d7f658ca15
06bfb6dfbc38105c699dea226a029df3ef673c33e4b8928dc4ec7fb8f761487d
1b93556f07c35ac0564d57e0743ccba231950962c6506c8d4a74a31cd66fd04c
88e7ddacd6b714d94d5322876bd50051479b7a0c686dc2e9eb06b3b7a0bc06c9
d22f6ada97dbffc1e7548e52163807f982b30b11a2a5109e71f42985102cccbd
dc445e2457ed31abf536871f90ff7cc96800a40b6bc033f37d45e3156a3b4fa9
e1e27af7b07eeedf5ce71a9255f0422816a6fc5849a483c6714e1b472044fa9d
2f141b72a2af0458993e27559395d8a8cdb0b752d79b1703541a61e728b55237
63ec83f825844c8f568130fa0ca5fc72266b2f55196769327024e66e04ca2483
31ca4fc861d823ebe940cb0f450998a251b6cd3511cb6adeba000080972f321a
aa1dd28cc0450dcf38761e4e63bd029c46c66a9dc907e5a2a4d1b2e4261c2dcd
139e767080fcdd816a19e664ece9e15769451d924d99288441607065cc928a8c
7182fb48a03f653a2b87d66409599d0d11dfb197ca7f969d2c8d72e38bf13590
3dd5ea8a14eb665ba6057d424f94e5e83757ffaab456578dbf038af04053b19e
debe56c4996bac3fc4cfc1e08a4d64981b17325d9cecb5b57e27ef349aef50a5
c81831992ca1d20397a959c60a2a401541f2e0d86a484003e7a9aa92a8beb8e2
Domains
www.bing.com
self.events.data.microsoft.com
ecs.office.com
x2.c.lencr.org
static.adtidy.org
login.live.com
settings-win.data.microsoft.com
google.com
time.windows.com
fe3cr.delivery.mp.microsoft.com
www.microsoft.com
ye2.c.lencr.org
ye.c.lencr.org
ocsp.digicert.com
x1.c.lencr.org
static.adguard.com
slscr.update.microsoft.com
crl.microsoft.com
th.bing.com
oneocsp.microsoft.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbq3l3%2f%2fa6adk8nray2gxzvayrhg4aqub6t%2b2v%2bxq3lso2d33ojhnyhhqoucezmaaaafuwohyjguzpcaaaaaaau%3d
http://static.adtidy.org/windows/setup.exe
http://x1.c.lencr.org/
http://x2.c.lencr.org/
http://ye.c.lencr.org/
http://ye2.c.lencr.org/123.crl
http://static.adguard.com/installer.v1.0.json
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://static.adguard.com/installer.v1.0.json
https://th.bing.com/th?id=odswg.iotdlocalicon&w=16&h=16&c=1&rs=1&p=0
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://activation-v2.sls.microsoft.com/slactivateproduct/slactivateproduct.asmx?configextension=retail
Last Seen at

Recent blog posts

post image
Making Threat Intelligence Work for SOC Teams...
watchers 2434
comments 0
post image
5 Critical Pain Points of Modern US SOCs and...
watchers 4755
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 7257
comments 0

What is MetaStealer malware?

MetaStealer is an information-stealing malware first observed in 2022. Initially announced on underground forums, MetaStealer is available as a malware-as-a-service (MaaS) for a subscription price of $125 per month or $1,000 for lifetime use.

Based on the RedLine stealer codebase, it includes several improvements, making it a more effective tool for credential theft and data exfiltration.

This malware has been distributed mainly through malspam campaigns, often using phishing emails to drop the malicious payload into the victim's machine.

MetaStealer has been observed in malvertising campaigns and cracked software distributed through compromised YouTube accounts. Its ability to steal login credentials, cryptocurrency wallet information, and browser-stored data has made it a popular choice among cybercriminals.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

MetaStealer malware technical details

The primary functionality of MetaStealer malware is to exfiltrate sensitive data from infected systems. Its key features include:

  • Steals login credentials, browser data, and cryptocurrency wallet info.
  • Sends stolen data to a remote command and control server.
  • Targets web browsers and email clients for stored credentials.
  • Modifies registry keys to reinfect systems after reboot.
  • Uses obfuscation to avoid detection by antivirus tools.
  • Spreads via phishing emails, malvertising, and cracked software.
  • Focuses on exploiting browsers to steal saved login info.
  • Available for subscription, making it widely accessible to attackers.
  • Can install additional malware on infected systems.

Once executed, MetaStealer is capable of establishing persistence on the infected system by modifying registry keys, making sure that it can reinfect the machine after a reboot. This persistence mechanism helps attackers maintain prolonged access to compromised systems.

MetaStealer's focus on browser exploitation is particularly dangerous, as it targets saved login credentials, autofill data, cookies, and other session information stored in web browsers. This gives attackers the ability to access a wide range of online accounts, from social media to financial services, without needing direct interaction from the victim.

MetaStealer malware execution process

To see how MetaStealer operates, let’s upload its sample to the ANY.RUN sandbox.

Metastealer process graph in ANY.RUN Metastealer process graph shown in ANY.RUN sandbox

Upon execution, MetaStealer may retrieve information about the operating system using winver.exe. It then duplicates itself, creating a copy that is placed in the local application data directory (%localappdata%\Microsoft\windows) and executed to maintain persistence.

To evade detection by Windows Defender, the malware may employ a PowerShell command to add exclusions for certain file types, allowing it to execute without triggering antivirus alerts. This command specifically targets executable files, facilitating the malware's operation without hindrance.

MetaStealer then collects extensive system details by executing systeminfo.exe.

Following this, it focuses on extracting sensitive information from installed web browsers, such as autofill data, cookies, and login credentials. This information is crucial for attackers as it can provide access to various online accounts and services.

After gathering the necessary information, MetaStealer prepares to send the stolen data back to the attackers, typically by establishing a connection to remote servers where the collected information is transmitted.

The exact mechanisms for exfiltration can vary but often involve HTTP POST requests to predefined command and control (C&C) servers.

In our example task, MetaStealer injects itself into the RegAsm system process to evade process-based defenses and possibly elevate privileges. The injected process attempted to connect to the C2 server, triggering a Suricata rule.

In some cases, the malware may arrive on the system alongside legitimate software, masquerading to avoid suspicion.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

MetaStealer malware distribution methods

MetaStealer is distributed through various methods, with attackers using different tactics to target victims. Some of the key distribution methods include:

  • Phishing emails with malicious attachments: One of the most common methods, MetaStealer is often delivered via phishing emails containing malicious attachments such as Word documents (.doc/.docx) or compressed files (.zip/.rar). These files may contain macros or embedded executables that launch the malware.
  • Malicious links: Emails can also include links that redirect the user to a malicious site where the malware is downloaded, disguised as legitimate software or documents.
  • Malvertising: Attackers sometimes use malicious online advertisements that lead to infected websites. These websites can either directly download MetaStealer or prompt users to install disguised malicious software.
  • Cracked software: MetaStealer has been found bundled with cracked or pirated software. Users who download software from untrusted sources may inadvertently install the malware along with what they believe to be legitimate applications.
  • Fake websites: Attackers may create fake websites that mimic legitimate ones, prompting users to download infected files or software updates that actually deliver MetaStealer.

Gathering threat intelligence on MetaStealer malware

To collect up-to-date intelligence on MetaStealer, use Threat Intelligence Lookup.

This service provides access to a large database filled with insights from millions of malware analysis sessions conducted in the ANY.RUN sandbox. With more than 40 customizable search parameters, you can find relevant data on threats including elements like IPs, domains, file names, and process artifacts.

Metastealer lookup search in ANY.RUN Search results for Metastealer in Threat Intelligence Lookup

For example, to gather intelligence on MetaStealer, you can search directly for its threat name or use a related artifact. By submitting a query like threatName:"MetaStealer", TI Lookup will bring up all associated samples and sandbox results relevant to this malware.

Get a 14-day free trial of Threat Intelligence Lookup along with the ANY.RUN sandbox

Conclusion

MetaStealer poses a significant threat due to its ability to steal credentials and spread through various distribution methods. It’s crucial to proactively analyze suspicious files and URLs to protect against this and similar malware.

ANY.RUN offers real-time threat analysis, letting users investigate suspicious files, track malware behavior, and collect actionable intelligence to improve security defenses.

Sign up for a free ANY.RUN account today and start analyzing emerging threats with no limits!

HAVE A LOOK AT

Bumblebee Loader screenshot
Bumblebee Loader
bumblebee
Bumblebee is a highly adaptable malware loader, often used by threat actors linked to the Conti and TrickBot cybercrime groups. Since its discovery in 2021, Bumblebee has been leveraged in phishing campaigns and email thread hijacking, primarily to distribute payloads like Cobalt Strike and ransomware. The malware employs obfuscation techniques, such as DLL injection and virtual environment detection, to avoid detection and sandbox analysis. Its command-and-control infrastructure and anti-analysis features allow it to persist on infected devices, where it enables further payload downloads and system compromise.
Read More
Maze screenshot
Maze
maze ransomware
Maze is ransomware — a malware type that encrypts the victim’s files and restores the data in exchange for a ransom payment. One of the most distinguishable features of Maze is that it is one of the first malware of the kind to publicly release stolen data.
Read More
Mispadu screenshot
Mispadu is a Windows banking trojan known for targeting online banking credentials, cryptocurrency wallets, and sensitive financial information. First identified in Latin America, the malware has continuously evolved with improved evasion techniques, phishing campaigns, and credential theft capabilities. Its reliance on social engineering rather than software vulnerabilities makes it an enduring threat to organizations whose employees interact with financial services online.
Read More
Keylogger screenshot
Keylogger
keylogger
A keylogger is a type of spyware that infects a system and has the ability to record every keystroke made on the device. This lets attackers collect personal information of victims, which may include their online banking credentials, as well as personal conversations. The most widespread vector of attack leading to a keylogger infection begins with a phishing email or link. Keylogging is also often present in remote access trojans as part of an extended set of malicious tools.
Read More
Oblivion RAT screenshot
Oblivion RAT
oblivion
Oblivion RAT is a sophisticated Android Remote Access Trojan (RAT) offered as Malware-as-a-Service (MaaS) on cybercrime forums for as little as $300 per month. It equips even novice attackers with a complete toolkit, including a web-based APK builder, dropper generator mimicking Google Play updates, and a real-time C2 panel. The RAT enables full device takeover, data theft, and financial fraud through deceptive social engineering and Accessibility Service abuse.
Read More
Prometei screenshot
Prometei
prometei
Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.
Read More