s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-MAL-py.rn_stealer

📛 Threat Title

Malware family: RN Stealer

Category: RN Stealer First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `py.rn_stealer`. Printable name: RN Stealer.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:arstechnica.com

    Once-hobbled Lumma Stealer is back with lures that are hard to resist ClickFix bait, combined with advanced Castleloader malware , is installing Lumma "at scale."

  • web:assets.kpmg.com

    Stealth tactics include scanning for VMs & debugging tools, hiding malicious activities in background processes, and using trusted system tools to avoid detection. Lumma Stealer's exploitation of legitimate services and use of obfuscated payloads to steal sensitive information underscores the need for robust security measures to combat such ...

  • web:blog.eclecticiq.com

    Conclusion and Mitigation Redline stealer , a popular threat to a variety of organizations, continues to make minor changes to remain a successful and prominent low-barrier-to-entry threat. In lieu of major development changes, latest variants exclude PowerShell, possibly to reduce the malware's footprint and automate via social media botnets.

  • web:furtivex.net

    Executive Summary This case study documents the successful remediation of a RedLine information stealer infection using DoesNotBelong as the only cleanup tool. The incident was handled publicly on a third‐party malware‐removal forum, without scripting, layered scanners, or follow‐up remediation utilities.

  • web:hunt.io

    Discover detailed profiles of malware families, including threat actor data, mitigation strategies, and targeted industries to enhance your defenses.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the RN Stealer malware family including references, samples and yara signatures.

  • web:thehackernews.com

    North Korea's Slow Pisces used LinkedIn lures in 2025 to drop RN Stealer malware on crypto developers.

  • web:www.breachsense.com

    Learn how to respond to malware incidents that steal credentials and session tokens. Discover how to remediate beyond device cleanup with this 7-step playbook.

  • web:www.cisa.gov

    Summary The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint advisory to disseminate known tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) associated with threat actors deploying the LummaC2 information stealer (infostealer) malware . LummaC2 malware is able to infiltrate victim computer ...

  • web:www.eset.com

    ESET Research exposes the backend operations of RedLine Stealer , a major infostealer malware , following its takedown by law enforcement. Discover how this malware -as-a-service empire operated and the impact of this global cybersecurity effort.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.