Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

MetaStealer

78
Global rank
112 infographic chevron month
Month rank
112 infographic chevron week
Week rank

MetaStealer is an info-stealing malware primarily targeting sensitive data like login credentials, payment details, and browser history. It typically infects systems via phishing emails or malicious downloads and can exfiltrate data to a command and control (C2) server. MetaStealer is known for its stealthy techniques, including evasion and persistence mechanisms, which make it difficult to detect. This malware has been actively used in various cyberattacks, particularly for financial theft and credential harvesting from individuals and organizations.

Stealer
Type
Unknown
Origin
1 March, 2022
First seen
18 September, 2026
Last seen

How to analyze MetaStealer with ANY.RUN

Type
Unknown
Origin
1 March, 2022
First seen
18 September, 2026
Last seen

IOCs

IP addresses
192.178.183.155
212.77.113.26
37.252.171.53
212.77.98.9
212.77.98.32
135.125.170.101
192.132.33.69
89.149.192.194
35.214.136.108
150.171.27.11
89.207.16.140
95.100.102.9
2.16.206.17
23.216.77.28
80.77.87.136
150.171.28.11
212.77.113.48
23.216.77.43
150.171.109.107
142.251.13.132
Hashes
d21021784cda31eeae5c8295e047a14bda6ed5a9b5963fca9e7ceb398a9c9179
189b1af95d661151e054cea10c91b3d754e4de4d3fecfb074c1fb29476f7167b
5154e165bd6c2cc0cfbcd8916498c7abab0497923bafcd5cb07673fe8480087d
b0083d0e5a5d62568f2982f2c3bdb3b22bd59cca636b9fd641f2f9440e4ea029
d2465a69360e10a6bb05ad3332607b4ecb810bf1f9b1a5a28fdfb621842efae8
1f03b3082883c94de09ea4c0b38092a45f2f7ca60c14889818a3e19057da34b8
a1e7a034adb8571f57b118052a0046882a7ae88db9f540b855217b02ff133669
e92c787df1d4c93ea84bfce7cf61448dca2879c4c2b9a9d8ad1e8c80f4001ac8
fdcb90174d3b2f5cb8b7a4205e60119419c728c1c76e5a2573aaa8058b6dd3a1
48878e2d1d5dcbd686358a180379d61f82aaf862fa2c4030933c1ad4e7299a20
49d57607054d07581044a39025ea0ff623185d5e8117b7325084db098795298d
c3904f63906db4346d2e0529285397c0ced3dbd5132dba250c3fcb28ed6a96df
1ef2a9fc7005712cd18effe0c6d644f6e1badce728c4bbbcdd675cd67d4fb9f7
09bd722b8c4cd442d56c7c730c2a363cf9bdfcb6a8971f00be002c90c40215b9
47cad1dbde4ad4d5eee0a7306c7e20df3f2a080a986cac5693c50b8ff1434b27
b94d06125457858a60c296993c6e23286bc1b1f7856553474da8afb4334e939c
272013c17922c5142893beb0655d6fe411c4f77b2a8140b4c35a4db49ac0a8b5
fd9b5998b98ee0ba86ed7687f215a1cdde90c00b0b1cd11dc83e3614389cb6ad
b103c0d7778d1694fdcab3aa28de6ee80aa9a10288355d2f47ee9ecf8a2462e6
d93acf4f35e97f83a145f2ba0ae278e403dedf38d8516a51e966e3d56af2d3f0
Domains
t.adx.opera.com
equativ-match.dotomi.com
aax-eu.amazon-adsystem.com
hbopenbid.pubmatic.com
connect.facebook.net
edge.microsoft.com
fonts.gstatic.com
c.amazon-adsystem.com
update.reasonsecurity.com
match.deepintent.com
slscr.update.microsoft.com
dnacdn.net
static.edge.microsoftapp.net
edge-cloud-resource-static.azureedge.net
crl.microsoft.com
match.adsrvr.org
pub.dv.tech
wirtualn-d.openx.net
csync.loopme.me
www.facebook.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:29sgwiwfedfczlafythca2sa3tpjzw7zdcyxhugh0ju&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d273%2526e%253d1
https://copilot.microsoft.com/c/api/user/eligibility
https://d2cppcvlcpza53.cloudfront.net/iy56dpz/czqc/dobreprogramy.pl_download_manager.exe
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://update.googleapis.com/service/update2/json?cup2key=14:rocrk5pd7yvw7kyyn5s-pg6adllvzcj44cpuivjeg54&cup2hreq=0c8016114a8aa1f2116deb0bc4f0d40356ec4c138d7fad445a944e590fec9be5
https://www.bing.com/api/shopping/v1/user/shoppingsettings?enabledservicefeaturesv2=edgeserverux.shopping.cashbackeumarkets,edgeserverux.shopping.msedgeshoppingcashbackdismisstimeout2s
https://clients2.googleusercontent.com/crx/blobs/abe5cl52ck7wwbndbvvaem8oys3yhboz1h4zjji-spceoodztoqtbav4glxcdddxfkjcfz5qxdftce2lflmfl4fmgxvilhkmrudcuedenzrbmgjjiqxwnwfy8qwxmtkglheaxlka5bx6yvrdaanj1smxvmii4akl_ln2/ghbmnnjooekpmoecnnnilnnbdlolhkhi_1_110_1_0.crx
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1789714718&lafgdate=0
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=arbitration_priority_list&version=24.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=edge_hub_apps_manifest_gz&version=4.11.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=domains_config_gz&version=3.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
Last Seen at

Recent blog posts

post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 2564
comments 0
post image
Enterprise Threat Intelligence Buying Guide:...
watchers 2932
comments 0
post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 4471
comments 0

What is MetaStealer malware?

MetaStealer is an information-stealing malware first observed in 2022. Initially announced on underground forums, MetaStealer is available as a malware-as-a-service (MaaS) for a subscription price of $125 per month or $1,000 for lifetime use.

Based on the RedLine stealer codebase, it includes several improvements, making it a more effective tool for credential theft and data exfiltration.

This malware has been distributed mainly through malspam campaigns, often using phishing emails to drop the malicious payload into the victim's machine.

MetaStealer has been observed in malvertising campaigns and cracked software distributed through compromised YouTube accounts. Its ability to steal login credentials, cryptocurrency wallet information, and browser-stored data has made it a popular choice among cybercriminals.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

MetaStealer malware technical details

The primary functionality of MetaStealer malware is to exfiltrate sensitive data from infected systems. Its key features include:

  • Steals login credentials, browser data, and cryptocurrency wallet info.
  • Sends stolen data to a remote command and control server.
  • Targets web browsers and email clients for stored credentials.
  • Modifies registry keys to reinfect systems after reboot.
  • Uses obfuscation to avoid detection by antivirus tools.
  • Spreads via phishing emails, malvertising, and cracked software.
  • Focuses on exploiting browsers to steal saved login info.
  • Available for subscription, making it widely accessible to attackers.
  • Can install additional malware on infected systems.

Once executed, MetaStealer is capable of establishing persistence on the infected system by modifying registry keys, making sure that it can reinfect the machine after a reboot. This persistence mechanism helps attackers maintain prolonged access to compromised systems.

MetaStealer's focus on browser exploitation is particularly dangerous, as it targets saved login credentials, autofill data, cookies, and other session information stored in web browsers. This gives attackers the ability to access a wide range of online accounts, from social media to financial services, without needing direct interaction from the victim.

MetaStealer malware execution process

To see how MetaStealer operates, let’s upload its sample to the ANY.RUN sandbox.

Metastealer process graph in ANY.RUN Metastealer process graph shown in ANY.RUN sandbox

Upon execution, MetaStealer may retrieve information about the operating system using winver.exe. It then duplicates itself, creating a copy that is placed in the local application data directory (%localappdata%\Microsoft\windows) and executed to maintain persistence.

To evade detection by Windows Defender, the malware may employ a PowerShell command to add exclusions for certain file types, allowing it to execute without triggering antivirus alerts. This command specifically targets executable files, facilitating the malware's operation without hindrance.

MetaStealer then collects extensive system details by executing systeminfo.exe.

Following this, it focuses on extracting sensitive information from installed web browsers, such as autofill data, cookies, and login credentials. This information is crucial for attackers as it can provide access to various online accounts and services.

After gathering the necessary information, MetaStealer prepares to send the stolen data back to the attackers, typically by establishing a connection to remote servers where the collected information is transmitted.

The exact mechanisms for exfiltration can vary but often involve HTTP POST requests to predefined command and control (C&C) servers.

In our example task, MetaStealer injects itself into the RegAsm system process to evade process-based defenses and possibly elevate privileges. The injected process attempted to connect to the C2 server, triggering a Suricata rule.

In some cases, the malware may arrive on the system alongside legitimate software, masquerading to avoid suspicion.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

MetaStealer malware distribution methods

MetaStealer is distributed through various methods, with attackers using different tactics to target victims. Some of the key distribution methods include:

  • Phishing emails with malicious attachments: One of the most common methods, MetaStealer is often delivered via phishing emails containing malicious attachments such as Word documents (.doc/.docx) or compressed files (.zip/.rar). These files may contain macros or embedded executables that launch the malware.
  • Malicious links: Emails can also include links that redirect the user to a malicious site where the malware is downloaded, disguised as legitimate software or documents.
  • Malvertising: Attackers sometimes use malicious online advertisements that lead to infected websites. These websites can either directly download MetaStealer or prompt users to install disguised malicious software.
  • Cracked software: MetaStealer has been found bundled with cracked or pirated software. Users who download software from untrusted sources may inadvertently install the malware along with what they believe to be legitimate applications.
  • Fake websites: Attackers may create fake websites that mimic legitimate ones, prompting users to download infected files or software updates that actually deliver MetaStealer.

Gathering threat intelligence on MetaStealer malware

To collect up-to-date intelligence on MetaStealer, use Threat Intelligence Lookup.

This service provides access to a large database filled with insights from millions of malware analysis sessions conducted in the ANY.RUN sandbox. With more than 40 customizable search parameters, you can find relevant data on threats including elements like IPs, domains, file names, and process artifacts.

Metastealer lookup search in ANY.RUN Search results for Metastealer in Threat Intelligence Lookup

For example, to gather intelligence on MetaStealer, you can search directly for its threat name or use a related artifact. By submitting a query like threatName:"MetaStealer", TI Lookup will bring up all associated samples and sandbox results relevant to this malware.

Get a 14-day free trial of Threat Intelligence Lookup along with the ANY.RUN sandbox

Conclusion

MetaStealer poses a significant threat due to its ability to steal credentials and spread through various distribution methods. It’s crucial to proactively analyze suspicious files and URLs to protect against this and similar malware.

ANY.RUN offers real-time threat analysis, letting users investigate suspicious files, track malware behavior, and collect actionable intelligence to improve security defenses.

Sign up for a free ANY.RUN account today and start analyzing emerging threats with no limits!

HAVE A LOOK AT

Kratos screenshot
Kratos
kratos
Kratos is a mature Phishing-as-a-Service (PhaaS) platform that evolved from the Sneaky2FA kit to specialize in stealing Microsoft 365 credentials through sophisticated Adversary-in-the-Middle (AiTM) techniques. The service provides low-skilled affiliates with a turnkey solution featuring an advanced administrative dashboard, integrated anti-bot defenses, and real-time data exfiltration via the Telegram Bot API. Although an international law enforcement action known as Operation Olympus Blade disrupted its central infrastructure in July 2026, the kit remains a primary example of the industrialization of modern cybercrime.
Read More
Caminho Loader screenshot
Caminho Loader
caminho caminholoader
Caminho Loader is a Brazilian-origin Loader-as-a-Service operation that uses steganography to conceal .NET payloads within image files hosted on legitimate platforms. Active since March 2025, it has delivered a variety of malware and infostealers to victims within multiple industries across South America, Africa, and Eastern Europe.
Read More
DarkGate screenshot
DarkGate
darkgate
DarkGate is a loader, which possesses extensive functionality, ranging from keylogging to crypto mining. Written in Delphi, this malware is known for the use of AutoIT scripts in its infection process. Thanks to this malicious software’s versatile architecture, it is widely used by established threat actors.
Read More
Roning Loader screenshot
Roning Loader
roning
RoningLoader is a multi-stage Windows loader designed to operate quietly while preparing systems for deeper compromise. It abuses trusted system tools and interferes with security controls to reduce the chances of early detection. Instead of acting as a final payload, it creates conditions for follow-on malware to execute more effectively. Its use of staged execution and code injection allows attackers to blend into legitimate activity and escalate impact. This makes early behavioral detection critical before the attack chain progresses further.
Read More
Greatness screenshot
Greatness is a Phishing-as-a-Service (PhaaS) platform that enables cybercriminals, even those with limited technical skills, to launch sophisticated phishing attacks primarily targeting Microsoft 365 (M365) credentials. It acts as a man-in-the-middle (MitM) proxy, facilitating credential theft and MFA bypass while providing affiliates with easy-to-use tools like attachment builders and Telegram notifications.
Read More
Meduza Stealer screenshot
Meduza Stealer is an information-stealing malware primarily targeting Windows systems, designed to harvest sensitive data such as login credentials, browsing histories, cookies, cryptocurrency wallets, and password manager data. It has advanced anti-detection mechanisms, allowing it to evade many antivirus programs. The malware is distributed through various means, including phishing emails and malicious links. It’s marketed on underground forums and Telegram channels.
Read More