TF-MAL-py.redtiger
📛 Threat Title
Malware family: RedTiger Stealer
Description
ThreatFox malware family `py.redtiger`. Printable name: RedTiger Stealer. Aliases: RedTiger Ste4ler,redtiger,redtiger-tools.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
py.redtiger
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/py.redtiger
IOC database
- Type
- domain
- Value
py.redtiger- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-py.redtiger
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/py.redtiger
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (8)
-
web:blog.eclecticiq.com
Conclusion and Mitigation Redline stealer , a popular threat to a variety of organizations, continues to make minor changes to remain a successful and prominent low-barrier-to-entry threat. In lieu of major development changes, latest variants exclude PowerShell, possibly to reduce the malware's footprint and automate via social media botnets.
-
web:cybersecuritynews.com
RedTiger is an open-source red-teaming tool repurposed by attackers to steal sensitive data from Discord users and gamers. Released in 2025 on GitHub, RedTiger bundles penetration-testing utilities, including network scanners and OSINT tools. But its infostealer module has gone rogue, with malicious payloads circulating online since early 2025.
-
web:d01a.github.io
Redline stealer is one of the most popular info stealers out there. The malware is available for sale on underground forums for a different subscription options.
-
web:github.com
RedTiger Stealer - Reverse Engineering Analysis. Contribute to 9dl/ redtiger -reversing development by creating an account on GitHub.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the RedTiger Stealer malware family including references, samples and yara signatures.
-
web:threatfox.abuse.ch
ThreatFox Database Indicators of Compromise (IOCs) on ThreatFox are associated with a certain malware fas. A malware sample can be associated with only one malware family . The page below gives you an overview on indicators of compromise associated with py. redtiger . You can also get this data through the ThreatFox API. Database Entry
-
web:www.akshayjain.blog
RedTiger an open source red team toolkit has been repurposed into an infostealer that targets Discord, browsers and crypto wallets. Read the technical analysis, IoCs, detection rules and mitigation guidance.
-
web:www.thaicert.or.th
428/68 Tuesday, October 28, 2025 Security researchers have discovered that threat actors repurposed the open-source penetration-testing tool RedTiger , modifying it into an info- stealer malware . Attackers compile the tool into binaries and give them game- or Discord-related names to trick users into downloading them.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.