Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate, RedLine/META/LummaC2/Rhadamanthys Activity

Infostealer Market Resilience (TL-2026-2708) is a medium-severity malware campaign, first published 2026-09-27. It is attributed to Distributed MaaS operator with medium confidence, affects Various (criminal MaaS operators) RedLine Stealer / META Stealer /, maps to 18 MITRE ATT&CK techniques (T1027.002, T1036, T1055.012), and is covered by 9 detection rules and 28 indicators of compromise.

Key facts for TL-2026-2708

Threat ID
TL-2026-2708
Severity
MEDIUM
Status
ACTIVE
Category
MALWARE
First published
2026-09-27
Last reviewed
2026-09-27
Attribution
Distributed MaaS operator
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
financial services, cryptocurrency, gaming, technology, retail, government administration
Target regions
Global, North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
28

Malware and tooling in Infostealer Market Resilience

Malware and tooling: Bumblebee - S1039, IcedID, Lumma Stealer - S1213, LummaC2 (Lumma Stealer), MetaStealer, Pikabot - S1145, RedLine Stealer - S1240, Rhadamanthys, Smoke Loader - S0226, SystemBC - S9001, Venom RAT, Trick Bot

An interrupted-time-series analysis of 44 million infostealer logs (June 2024-June 2026) found that three of four law-enforcement takedowns against RedLine, META, LummaC2, and Rhadamanthys infrastructure produced net-positive displacement rather than suppression, with RedLine volume rising roughly +70-200% in the 14-90 days after Operation Magnus (p<=0.045). Only the coordinated FBI/DOJ/Europol/Microsoft action against LummaC2 in May 2025 - which struck technical infrastructure, distribution, monetization, and criminal trust simultaneously - produced statistically significant, lasting suppression (-46% at 14 days, -39% at 90 days).

How Infostealer Market Resilience works

Flare Academy's 'Real-World Impact of Takedowns on the Infostealer Market' (25 September 2026) applies an interrupted time series (ITS) design with symmetric +/-14/30/60/90-day windows to a corpus of ~44 million infostealer logs collected June 2024-June 2026, one record per compromised host, attributed via syntactic fingerprinting and telemetry-based classification. The study evaluates four distinct law-enforcement operations against the infostealer malware-as-a-service (MaaS) ecosystem: Operation Magnus (28 October 2024, Dutch National Police/FBI/Eurojust coalition against RedLine and META Stealer infrastructure), the original Operation Endgame (27-29 May 2024, France/Germany/Netherlands-led action against the dropper ecosystem - IcedID, SystemBC, Pikabot, Bumblebee, Smokeloader, Trickbot - that feeds infostealer distribution), Operation Secure (INTERPOL-led, January-April 2025, 26-country Asia-Pacific action against LummaC2 and related stealer infrastructure), and the FBI/DOJ/Europol/Microsoft action against LummaC2 (19-21 May 2025). Three of the four produced net-positive volume changes in the targeted or adjacent families: RedLine rose ~+70% at 14 days and ~+200% at 90 days after Magnus (p=0.032 / p=0.045); total dropper-ecosystem-linked stealer volume rose +41% at 90 days after the original Endgame (p=0.042); LummaC2 volume rose +75% at 90 days despite Operation Secure (p=0.004); and Rhadamanthys showed no measurable statistical response to the later Operation Endgame Phase 3 action because its market share was still negligible at that time. Only the May 2025 FBI/DOJ/Europol/Microsoft LummaC2 action - which seized 2,300+ domains (five core panel domains plus subdomains) and disabled five C2 servers, corroborated by the joint FBI/CISA advisory AA25-141B published the same week - produced a statistically significant and durable drop: -46% at 14 days (p=0.042), -34% at 30 days, and -39% at 90 days (p=0.001/0.011 depending on window). Flare's structural explanation is that the LummaC2 action degraded technical infrastructure, distribution channels, monetization mechanisms, and criminal-forum trust simultaneously, whereas the other three operations struck only a single layer (infrastructure alone) and left distribution/monetization/trust intact, letting affiliates and buyers migrate to the next available family. This is corroborated by independent reporting: ESET's backend analysis of the RedLine/META operation (8 November 2024) found both stealers shared a single creator, a common dead-drop-resolver scheme (GitHub-hosted encrypted server lists), and REST-API backends (fivto[.]online for RedLine, spasshik[.]xyz for META) that were largely intact at seizure time outside the three Dutch servers and two domains actually taken; and the November 2025 Operation Endgame Phase 3/3.0 action against Rhadamanthys, VenomRAT, and the Elysium botnet (1,025 servers, 20 domains, one arrest in Greece) came after Rhadamanthys had already absorbed significant displaced volume from the earlier, less-durable takedowns. For SOC and threat-intel consumers, the operational takeaway is that a single-family takedown announcement should not be scored as an overall reduction in infostealer exposure risk; defenders should expect volume migration to remaining active families (RedLine, META, Rhadamanthys, StealC, Vidar) unless the action visibly targets infrastructure, distribution, and monetization together, as the May 2025 LummaC2 action did.

MITRE ATT&CK techniques used in TL-2026-2708

Defense Evasion

T1027.002 Software Packing; T1036 Masquerading; T1055.012 Process Hollowing; T1497.001 System Checks

Execution

T1059.001 PowerShell; T1204.002 Malicious File

Command and Control

T1071.001 Web Protocols; T1573.002 Asymmetric Cryptography

Discovery

T1082 System Information Discovery; T1217 Browser Information Discovery; T1518.001 Security Software Discovery

Collection

T1119 Automated Collection

Credential Access

T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers

Persistence

T1547.001 Registry Run Keys / Startup Folder

Initial Access

T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link

Impact

T1657 Financial Theft

Affected products and versions in Infostealer Market Resilience

  • Various (criminal MaaS operators) — RedLine Stealer / META Stealer / LummaC2 (Lumma Stealer) / Rhadamanthys - Windows information-stealing malware families
    Vulnerable versions: All actively-sold builds, 2020-2026
    Fixed in: N/A - malware families, not a vendor patchable product
  • Microsoft — Windows desktop endpoints (any supported version running a targeted browser)
    Vulnerable versions: Any Windows host that executes an untrusted binary or malicious script
    Fixed in: N/A

Remediation for Infostealer Market Resilience

Immediate actions

  • Block/sinkhole known LummaC2 C2 domains and RedLine/META backend domains (e.g., fivto[.]online, spasshik[.]xyz) at DNS and perimeter egress filtering
  • Hunt for the CISA AA25-141B LummaC2 hash and domain indicators across EDR telemetry and proxy logs
  • Force credential rotation and browser-session/cookie invalidation on any host with stealer-log indicators, given confirmed session-cookie theft (T1539) capability
  • Alert on dllhost.exe (COM surrogate) spawning unexpected child processes or making outbound network connections, a documented LummaC2 masquerading pattern

Workarounds

  • Enforce enterprise browser policy to disable built-in password-manager autofill and shorten session-token lifetimes, reducing the resale value of any successful stealer-log capture
  • Restrict outbound access to Telegram Bot API endpoints and raw IP-literal HTTP destinations from standard user workstations to disrupt common infostealer exfiltration channels

Longer-term hardening

  • Deploy phishing-resistant MFA so stolen browser credentials alone cannot be replayed for account takeover
  • Application allowlisting to block unsigned/unauthorized PE and PowerShell execution, the dominant initial-execution path for all four families
  • Subscribe to continuous infostealer-log-market monitoring (Flare, Group-IB, Trend Micro, KELA-class feeds) rather than treating any single takedown announcement as a standalone risk-reduction signal
  • Track displacement, not just suppression: after any single-family infostealer takedown, re-baseline detection coverage against the remaining active families (RedLine, META, Rhadamanthys, StealC, Vidar) rather than assuming reduced overall exposure

Timeline of Infostealer Market Resilience

  • France, Germany, and the Netherlands, with Europol/Eurojust support, launch the original Operation Endgame (27-29 May 2024) against the dropper ecosystem feeding infostealer distribution - IcedID, SystemBC, Pikabot, Bumblebee, Smokeloader, and Trickbot - seizing 100+ servers and ~2,000 domains and making 4 arrests.
  • Flare's 44-million-log infostealer dataset analysis window begins (June 2024).
  • spasshik[.]xyz, the META Stealer REST-API backend panel domain, is first observed active per ESET's later infrastructure analysis.
  • fivto[.]online, the RedLine Stealer REST-API backend panel domain, is first observed active per ESET's later infrastructure analysis.
  • Operation Magnus: Dutch National Police, FBI, and international partners (Belgium, Portugal, UK, Australia), coordinated by Eurojust, seize 3 servers and 2 domains supporting RedLine and META Stealer infrastructure in the Netherlands; alleged RedLine administrator Maxim Rudometov is indicted in the US Western District of Texas and two suspected customers are arrested in Belgium.
  • ESET Research publishes 'Life on a crooked RedLine,' a backend infrastructure analysis showing RedLine and META Stealer share a single creator, a GitHub-hosted dead-drop-resolver scheme, and 1,000+ unique control-panel-hosting IP addresses largely untouched by Operation Magnus.
  • INTERPOL-led Operation Secure runs January-April 2025 across 26 countries (Asia-Pacific focus), seizing 41 servers and 20,000+ malicious IPs/domains and arresting 32 suspects linked to LummaC2, RisePro, and META Stealer infrastructure.
  • US authorities seize the first two core LummaC2 user-panel domains.
  • LummaC2 administrators stand up three replacement panel domains after the initial seizure; these are seized the following day.
  • CISA and FBI jointly publish advisory AA25-141B detailing LummaC2 TTPs, MITRE ATT&CK mappings, and IOCs (hashes and 100+ C2 domains).
  • DOJ, Microsoft's Digital Crimes Unit, Europol, Japan's Cybercrime Control Center, Cloudflare, and Bitsight complete the coordinated LummaC2 takedown: 2,300+ domains disrupted (1,300+ sinkholed) and 5 C2 servers disabled; FBI identifies 394,000 LummaC2 infections between 16 March and 16 May 2025 alone, against a lifetime total of 1.7 million compromised devices.
  • Operation Endgame Phase 3 ('Endgame 3.0'): international law enforcement (Australia, Canada, Denmark, France, Germany, Greece, US) takes down 1,025 servers and 20 domains tied to Rhadamanthys, VenomRAT, and the Elysium botnet, searches 11 locations, and arrests the alleged VenomRAT administrator in Greece; 525,303 unique Rhadamanthys infections are identified across 226 countries/territories between March and November 2025.
  • Flare's 44-million-log infostealer dataset analysis window closes (June 2026).
  • Flare Academy publishes 'Real-World Impact of Takedowns on the Infostealer Market,' the interrupted-time-series analysis showing 3 of 4 operations produced net displacement rather than suppression.

Sources cited for Infostealer Market Resilience

More in malware

Detection coverage for TL-2026-2708

As of 2026-09-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2708 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats