s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-py.redtiger

📛 Threat Title

Malware family: RedTiger Stealer

Category: RedTiger Stealer First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `py.redtiger`. Printable name: RedTiger Stealer. Aliases: RedTiger Ste4ler,redtiger,redtiger-tools.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain py.redtiger VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/py.redtiger

IOC database

Type
domain
Value
py.redtiger
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-py.redtiger

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/py.redtiger

References (1)

Remediations (8)

  • web:blog.eclecticiq.com

    Conclusion and Mitigation Redline stealer , a popular threat to a variety of organizations, continues to make minor changes to remain a successful and prominent low-barrier-to-entry threat. In lieu of major development changes, latest variants exclude PowerShell, possibly to reduce the malware's footprint and automate via social media botnets.

  • web:cybersecuritynews.com

    RedTiger is an open-source red-teaming tool repurposed by attackers to steal sensitive data from Discord users and gamers. Released in 2025 on GitHub, RedTiger bundles penetration-testing utilities, including network scanners and OSINT tools. But its infostealer module has gone rogue, with malicious payloads circulating online since early 2025.

  • web:d01a.github.io

    Redline stealer is one of the most popular info stealers out there. The malware is available for sale on underground forums for a different subscription options.

  • web:github.com

    RedTiger Stealer - Reverse Engineering Analysis. Contribute to 9dl/ redtiger -reversing development by creating an account on GitHub.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the RedTiger Stealer malware family including references, samples and yara signatures.

  • web:threatfox.abuse.ch

    ThreatFox Database Indicators of Compromise (IOCs) on ThreatFox are associated with a certain malware fas. A malware sample can be associated with only one malware family . The page below gives you an overview on indicators of compromise associated with py. redtiger . You can also get this data through the ThreatFox API. Database Entry

  • web:www.akshayjain.blog

    RedTiger an open source red team toolkit has been repurposed into an infostealer that targets Discord, browsers and crypto wallets. Read the technical analysis, IoCs, detection rules and mitigation guidance.

  • web:www.thaicert.or.th

    428/68 Tuesday, October 28, 2025 Security researchers have discovered that threat actors repurposed the open-source penetration-testing tool RedTiger , modifying it into an info- stealer malware . Attackers compile the tool into binaries and give them game- or Discord-related names to trick users into downloading them.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.