Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate, RedLine/META/LummaC2/Rhadamanthys Activity
Infostealer Market Resilience (TL-2026-2708) is a medium-severity malware campaign, first published 2026-09-27. It is attributed to Distributed MaaS operator with medium confidence, affects Various (criminal MaaS operators) RedLine Stealer / META Stealer /, maps to 18 MITRE ATT&CK techniques (T1027.002, T1036, T1055.012), and is covered by 9 detection rules and 28 indicators of compromise.
Key facts for TL-2026-2708
- Threat ID
- TL-2026-2708
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-09-27
- Last reviewed
- 2026-09-27
- Attribution
- Distributed MaaS operator
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- financial services, cryptocurrency, gaming, technology, retail, government administration
- Target regions
- Global, North America, Europe, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 28
Malware and tooling in Infostealer Market Resilience
Malware and tooling: Bumblebee - S1039, IcedID, Lumma Stealer - S1213, LummaC2 (Lumma Stealer), MetaStealer, Pikabot - S1145, RedLine Stealer - S1240, Rhadamanthys, Smoke Loader - S0226, SystemBC - S9001, Venom RAT, Trick Bot
An interrupted-time-series analysis of 44 million infostealer logs (June 2024-June 2026) found that three of four law-enforcement takedowns against RedLine, META, LummaC2, and Rhadamanthys infrastructure produced net-positive displacement rather than suppression, with RedLine volume rising roughly +70-200% in the 14-90 days after Operation Magnus (p<=0.045). Only the coordinated FBI/DOJ/Europol/Microsoft action against LummaC2 in May 2025 - which struck technical infrastructure, distribution, monetization, and criminal trust simultaneously - produced statistically significant, lasting suppression (-46% at 14 days, -39% at 90 days).
How Infostealer Market Resilience works
Flare Academy's 'Real-World Impact of Takedowns on the Infostealer Market' (25 September 2026) applies an interrupted time series (ITS) design with symmetric +/-14/30/60/90-day windows to a corpus of ~44 million infostealer logs collected June 2024-June 2026, one record per compromised host, attributed via syntactic fingerprinting and telemetry-based classification. The study evaluates four distinct law-enforcement operations against the infostealer malware-as-a-service (MaaS) ecosystem: Operation Magnus (28 October 2024, Dutch National Police/FBI/Eurojust coalition against RedLine and META Stealer infrastructure), the original Operation Endgame (27-29 May 2024, France/Germany/Netherlands-led action against the dropper ecosystem - IcedID, SystemBC, Pikabot, Bumblebee, Smokeloader, Trickbot - that feeds infostealer distribution), Operation Secure (INTERPOL-led, January-April 2025, 26-country Asia-Pacific action against LummaC2 and related stealer infrastructure), and the FBI/DOJ/Europol/Microsoft action against LummaC2 (19-21 May 2025). Three of the four produced net-positive volume changes in the targeted or adjacent families: RedLine rose ~+70% at 14 days and ~+200% at 90 days after Magnus (p=0.032 / p=0.045); total dropper-ecosystem-linked stealer volume rose +41% at 90 days after the original Endgame (p=0.042); LummaC2 volume rose +75% at 90 days despite Operation Secure (p=0.004); and Rhadamanthys showed no measurable statistical response to the later Operation Endgame Phase 3 action because its market share was still negligible at that time. Only the May 2025 FBI/DOJ/Europol/Microsoft LummaC2 action - which seized 2,300+ domains (five core panel domains plus subdomains) and disabled five C2 servers, corroborated by the joint FBI/CISA advisory AA25-141B published the same week - produced a statistically significant and durable drop: -46% at 14 days (p=0.042), -34% at 30 days, and -39% at 90 days (p=0.001/0.011 depending on window). Flare's structural explanation is that the LummaC2 action degraded technical infrastructure, distribution channels, monetization mechanisms, and criminal-forum trust simultaneously, whereas the other three operations struck only a single layer (infrastructure alone) and left distribution/monetization/trust intact, letting affiliates and buyers migrate to the next available family. This is corroborated by independent reporting: ESET's backend analysis of the RedLine/META operation (8 November 2024) found both stealers shared a single creator, a common dead-drop-resolver scheme (GitHub-hosted encrypted server lists), and REST-API backends (fivto[.]online for RedLine, spasshik[.]xyz for META) that were largely intact at seizure time outside the three Dutch servers and two domains actually taken; and the November 2025 Operation Endgame Phase 3/3.0 action against Rhadamanthys, VenomRAT, and the Elysium botnet (1,025 servers, 20 domains, one arrest in Greece) came after Rhadamanthys had already absorbed significant displaced volume from the earlier, less-durable takedowns. For SOC and threat-intel consumers, the operational takeaway is that a single-family takedown announcement should not be scored as an overall reduction in infostealer exposure risk; defenders should expect volume migration to remaining active families (RedLine, META, Rhadamanthys, StealC, Vidar) unless the action visibly targets infrastructure, distribution, and monetization together, as the May 2025 LummaC2 action did.
MITRE ATT&CK techniques used in TL-2026-2708
Defense Evasion
T1027.002 Software Packing; T1036 Masquerading; T1055.012 Process Hollowing; T1497.001 System Checks
Execution
T1059.001 PowerShell; T1204.002 Malicious File
Command and Control
T1071.001 Web Protocols; T1573.002 Asymmetric Cryptography
Discovery
T1082 System Information Discovery; T1217 Browser Information Discovery; T1518.001 Security Software Discovery
Collection
Credential Access
T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers
Persistence
T1547.001 Registry Run Keys / Startup Folder
Initial Access
T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link
Impact
Affected products and versions in Infostealer Market Resilience
- Various (criminal MaaS operators) — RedLine Stealer / META Stealer / LummaC2 (Lumma Stealer) / Rhadamanthys - Windows information-stealing malware families
Vulnerable versions: All actively-sold builds, 2020-2026
Fixed in: N/A - malware families, not a vendor patchable product - Microsoft — Windows desktop endpoints (any supported version running a targeted browser)
Vulnerable versions: Any Windows host that executes an untrusted binary or malicious script
Fixed in: N/A
Remediation for Infostealer Market Resilience
Immediate actions
- Block/sinkhole known LummaC2 C2 domains and RedLine/META backend domains (e.g., fivto[.]online, spasshik[.]xyz) at DNS and perimeter egress filtering
- Hunt for the CISA AA25-141B LummaC2 hash and domain indicators across EDR telemetry and proxy logs
- Force credential rotation and browser-session/cookie invalidation on any host with stealer-log indicators, given confirmed session-cookie theft (T1539) capability
- Alert on dllhost.exe (COM surrogate) spawning unexpected child processes or making outbound network connections, a documented LummaC2 masquerading pattern
Workarounds
- Enforce enterprise browser policy to disable built-in password-manager autofill and shorten session-token lifetimes, reducing the resale value of any successful stealer-log capture
- Restrict outbound access to Telegram Bot API endpoints and raw IP-literal HTTP destinations from standard user workstations to disrupt common infostealer exfiltration channels
Longer-term hardening
- Deploy phishing-resistant MFA so stolen browser credentials alone cannot be replayed for account takeover
- Application allowlisting to block unsigned/unauthorized PE and PowerShell execution, the dominant initial-execution path for all four families
- Subscribe to continuous infostealer-log-market monitoring (Flare, Group-IB, Trend Micro, KELA-class feeds) rather than treating any single takedown announcement as a standalone risk-reduction signal
- Track displacement, not just suppression: after any single-family infostealer takedown, re-baseline detection coverage against the remaining active families (RedLine, META, Rhadamanthys, StealC, Vidar) rather than assuming reduced overall exposure
Timeline of Infostealer Market Resilience
- France, Germany, and the Netherlands, with Europol/Eurojust support, launch the original Operation Endgame (27-29 May 2024) against the dropper ecosystem feeding infostealer distribution - IcedID, SystemBC, Pikabot, Bumblebee, Smokeloader, and Trickbot - seizing 100+ servers and ~2,000 domains and making 4 arrests.
- Flare's 44-million-log infostealer dataset analysis window begins (June 2024).
- spasshik[.]xyz, the META Stealer REST-API backend panel domain, is first observed active per ESET's later infrastructure analysis.
- fivto[.]online, the RedLine Stealer REST-API backend panel domain, is first observed active per ESET's later infrastructure analysis.
- Operation Magnus: Dutch National Police, FBI, and international partners (Belgium, Portugal, UK, Australia), coordinated by Eurojust, seize 3 servers and 2 domains supporting RedLine and META Stealer infrastructure in the Netherlands; alleged RedLine administrator Maxim Rudometov is indicted in the US Western District of Texas and two suspected customers are arrested in Belgium.
- ESET Research publishes 'Life on a crooked RedLine,' a backend infrastructure analysis showing RedLine and META Stealer share a single creator, a GitHub-hosted dead-drop-resolver scheme, and 1,000+ unique control-panel-hosting IP addresses largely untouched by Operation Magnus.
- INTERPOL-led Operation Secure runs January-April 2025 across 26 countries (Asia-Pacific focus), seizing 41 servers and 20,000+ malicious IPs/domains and arresting 32 suspects linked to LummaC2, RisePro, and META Stealer infrastructure.
- US authorities seize the first two core LummaC2 user-panel domains.
- LummaC2 administrators stand up three replacement panel domains after the initial seizure; these are seized the following day.
- CISA and FBI jointly publish advisory AA25-141B detailing LummaC2 TTPs, MITRE ATT&CK mappings, and IOCs (hashes and 100+ C2 domains).
- DOJ, Microsoft's Digital Crimes Unit, Europol, Japan's Cybercrime Control Center, Cloudflare, and Bitsight complete the coordinated LummaC2 takedown: 2,300+ domains disrupted (1,300+ sinkholed) and 5 C2 servers disabled; FBI identifies 394,000 LummaC2 infections between 16 March and 16 May 2025 alone, against a lifetime total of 1.7 million compromised devices.
- Operation Endgame Phase 3 ('Endgame 3.0'): international law enforcement (Australia, Canada, Denmark, France, Germany, Greece, US) takes down 1,025 servers and 20 domains tied to Rhadamanthys, VenomRAT, and the Elysium botnet, searches 11 locations, and arrests the alleged VenomRAT administrator in Greece; 525,303 unique Rhadamanthys infections are identified across 226 countries/territories between March and November 2025.
- Flare's 44-million-log infostealer dataset analysis window closes (June 2026).
- Flare Academy publishes 'Real-World Impact of Takedowns on the Infostealer Market,' the interrupted-time-series analysis showing 3 of 4 operations produced net displacement rather than suppression.
Sources cited for Infostealer Market Resilience
- Real-World Impact of Takedowns on the Infostealer Market
- Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations (AA25-141B)
- Justice Department Seizes Domains Behind Major Information-Stealing Malware Operation
- FBI and Europol Disrupt Lumma Stealer Malware Network Linked to 10 Million Infections
- Largest ever operation against botnets hits dropper malware ecosystem
- Operation Endgame: Coordinated Worldwide Law Enforcement Action Against Network of Cybercriminals
- End of the game for cybercrime infrastructure: 1025 servers taken down
- Operation Endgame Dismantles Rhadamanthys, Venom RAT, and Elysium Botnet in Global Crackdown
- 1,000+ Servers Hit in Law Enforcement Takedown of Rhadamanthys, VenomRAT, Elysium
- Life on a crooked RedLine: Analyzing the infamous infostealer's backend
- Operation Magnus targets Redline, Meta infostealers
- 20,000 malicious IPs and domains taken down in INTERPOL infostealer crackdown
- Operation Secure: Trend Micro's Threat Intelligence Fuels INTERPOL's Infostealer Infrastructure Takedown
- RedLine Stealer, Software S1240
- Lumma Stealer, Software S1213
More in malware
- MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto Wallet Campaign
- TWEAKOS Stealer: Discord Token Theft and Telegram Account-Takeover Marketplace
- ClickFix Campaign Abuses Compromised Ukrainian Websites to Deploy Psychedelic Stealer
- CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Theft
- The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environments
Detection coverage for TL-2026-2708
As of 2026-09-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2708 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.