Introduction
On October 28, 2024, the Dutch National Police (Politie), in close collaboration with the FBI and other partners of the international law enforcement task force Operation Magnus, successfully disrupted the operations of the RedLine and Meta infostealers. As part of this operation, the U.S. Department of Justice (DOJ) unsealed charges against Maxim Rudometov, identifying him as one of the developers and administrators behind RedLine Infostealer.
This research uncovers the story of RedLine, exploring operations while profiling Maxim Rudometov and examining his personal journey. The information used in this research includes facts revealed in the indictment as part of law enforcement actions, as well as findings from Analyst1 and OSINord published earlier this year.
RedLine: A Devil in the Details
February 2020. The world faced the COVID-19 pandemic, with people everywhere glued to their computers for work, connection, and distraction. Another kind of virus emerged in the shadows – RedLine, a digital espionage tool and a license to steal.
On February 19, 2020, a member of the DARK2WEB forum, using the alias REDGlade, posted a message promoting RedLine infostealer and highlighting its extensive features and capabilities. RedLine, marketed as “commodity malware” through a Malware-as-a-Service (MaaS) model, enables the theft of victims’ passwords, cryptocurrency wallets, and other private information. Once executed, RedLine would harvest financial data, saved credentials, and cryptocurrency details, effectively stripping away its victims’ digital privacy and security. In the underground cybercrime ecosystem, this stolen information, often called “logs,” is popular among cybercriminals and frequently used for a range of illicit activities, from identity theft to financial fraud and other types of cybercrime.

Source: DARK2WEB
RedLine was crafted to outsmart even the most vigilant antivirus systems, using code obfuscation to slip past cybersecurity defenses. To keep itself under the radar and avoid trouble from Russian law enforcement, it came equipped with a built-in blocker that whitelists the Commonwealth of Independent States (CIS). While Russian-speaking targets were off-limits, RedLine’s affiliates had no such reservations for others. Exploiting COVID-19 chaos, they crafted phishing emails to lure unsuspecting victims.
One notable target was the Folding@Home project, a distributed computing initiative that lets users download software to harness their CPU and GPU cycles to research drug treatments and better understand diseases. According to Proofpoint research, thousands of phishing emails attempted to deliver RedLine Infostealer via links embedded in the messages. Legitimate Folding@Home participants were required to download the official application from the project’s website. Still, RedLine actors tried to deceive victims into downloading a malicious version of the software via email links.
In addition to DarkWeb forums, RedLine was heavily promoted on Telegram, where clients, or “affiliates,” could purchase its service. Telegram, in particular, played a pivotal role in boosting RedLine’s business. RedLine’s now-defunct Telegram accounts included a channel, a chat group, and a bot that streamlined the process, allowing clients to purchase the malicious tool quickly and conveniently, making RedLine more accessible than ever. Initially, the malware was offered for $100 per month, with a Lite version available for $150 and a PRO version for lifetime use priced at $200. Later, the pricing structure was adjusted, offering a subscription fee of $150 per month or a one-time payment of $900 in cryptocurrency.

Source: Telegram
Very quickly, RedLine became a national security threat. In early 2021, the FBI and NCIS received reports from several U.S. defense contractors whose systems had been breached. Investigators soon discovered that RedLine had infected the computers of defense employees, where it lay quietly, harvesting sensitive data before escaping. Victims ranged from a U.S. defense contractor to a multinational technology giant, where a notorious hacking group used RedLine to gain access to employee accounts. In another case, a Portage, Indiana, resident reported losing $370,000 worth of cryptocurrency after RedLine accessed their digital wallet. Ultimately, the FBI estimated that RedLine had compromised millions of devices across hundreds of thousands of networks, leading to significant financial losses for its victims.
Operation Magnus – Ready or Not, Here I Come
On October 28, 2024, the Dutch National Police (Politie), in close cooperation with the FBI and other partners of the international law enforcement task force Operation Magnus, disrupted the operations of the RedLine and Meta infostealers. Three servers were taken down in the Netherlands, two domains were seized, charges were unsealed in the United States, and two people were taken into custody in Belgium. To assist RedLine and Meta victims, ESET released a tool to check their systems for signs of infection.
The dedicated website for Operation Magnus includes a video that sarcastically imitates a promotional ad for infostealers, stating: “This is the final update for Redline and Meta. This update has been made in partnership with international law enforcement. We gained full access to all Redline and Meta servers. Did you know they are actually pretty much the same? This version of Redline and Meta includes: unique insights in your data. Usernames, passwords, IP addresses, timestamps, registration dates and much more! All the Redline and Meta source code including the license servers, REST-API-servers, panels, stealers and Telegram bots. VIP status for ALL Redline and Meta users where VIP means Very Important to the Police. Thank you for installing this update. We are looking forward to seeing you soon.”

Source: operation-magnus[.]com
As part of the video, law enforcement also revealed 88 monikers, likely referring to users with VIP status, with VIP sarcastically redefined as “Very Important to the Police,” according to the message. Similar to the approach used in Operation EndGame and Operation Cronos covered by Analyst1 earlier this year, law enforcement employed psychological pressure, including a countdown for another announcement the following day, accompanied by the message: “Stay tuned for more news.”
Law enforcement intensified the pressure, creating an account under the name OP_Magnus on the Russian-speaking underground forum XSS. The account was swiftly blocked, highlighting the forum’s strict moderation and inclination toward removing content that could harm the reputation and image of Russian-speaking cybercrime. According to the message, RedLine users were also personally notified by law enforcement, each receiving a message about impending legal actions and warnings that authorities would pursue those involved in illicit activities to bring them to justice.

Source: XSS forum
The Department of Justice (DOJ) unsealed charges against Maxim Rudometov, identifying him as one of the developers and administrators of RedLine Infostealer. According to the unsealed indictment against Rudometov, he was deeply involved in accessing and managing RedLine’s infrastructure, associating with various cryptocurrency accounts to receive and launder payments, and possessing RedLine malware. Rudometov’s story offers yet another compelling case for studying and analyzing criminal profiles, uncovering the personality traits and life events that paved his path to cybercrime. To better understand his journey, let’s delve into his personal life and the factors that shaped his choices.
The Man Behind RedLine – Rudometov Story
Born on March 21, 1999, and now 25, Maxim Rudometov was interested in computers and hacking from an early age. On June 23, 2009, at 10 years old, he registered an account on VKontakte, Russia’s largest social media platform, popular in Russia and other former Soviet Union countries. Under “Specialty” at the school he attended, according to the account in Luhansk, Ukraine, he brazenly wrote: Hacker. And in his “About Me” section, he shared, “I like to go out, I sit at my computer like an owl.” Rudometov began carving out a place for himself in the digital underworld from a very young age, drawn to its darker side.

including personal information provided during registration
Source: VKontakte
His passion for coding and hacking progressed, giving way to his apparent entrepreneurial nature. Examining Rudometov’s digital footprint around 2012 reveals that, at 14, he was identified selling stolen accounts for online games on the forum zhyk[.]org, accepting payments in both Russian rubles and Ukrainian hryvnias. Registered under the username Fenix19971, Rudometov made little effort to conceal his true identity. He openly stated his name as “Maxim” and even provided a link to his other VKontakte account.
In another forum post, Rudometov shared additional personal details that would later prove pivotal in linking him to his persona and the illicit activities he pursued as his underground career unfolded. This information, which ultimately became key evidence for law enforcement, included his email address ([email protected]), a Skype account registered under the username bloodzz.fenix, and his VKontakte account registered on April 11, 2012, under the username navi_ghacking with the name stated as Maxim Rudometov. Adding to the trail, he repeatedly stated his real name, Maxim, on the forum – another clue to his true identity.

Source: zhyk[.]org
Following the trail of Rudometov’s digital footprint reveals yet another business endeavor he pursued. On July 14, 2015, at 16, he created a VKontakte group called “Custom Software Writing” to promote his development services. His VKontakte account under the username navi_ghacking mentioned above was listed as a point of contact. Positioning himself as a “C# developer,” Rudometov offered software tools such as VkApiChecker and VkGroupParser. “I write custom software,” he declared in a post, actively advertising his programming expertise and services.

Source: VKontakte
Rudometov’s involvement in illicit activities, such as selling PayPal accounts – “logs” – was observed around the same time in 2015. The GHackiHG account, registered on the YouHack forum on May 3, 2015, has posted 35 messages since its creation, offering a variety of illicit goods. The listed contact details, stated in the indictment, included the same email address ([email protected]) and a Skype account registered under the username bloodzz.fenix, both of which were previously mentioned by Rudometov in 2012 on the zhyk[.]org forum.

Source: YouHack Forum
In addition, in one of these messages, Rudometov shared a link to his personal VKontakte page, which he registered on June 7, 2015, under the name Maxim Rudometov (VKontakte later blocked this page for suspicious activity) An investigation of this VKontakte account’s history revealed that it listed his birthdate as March 21 and his residence as Luhansk, Ukraine, matching the personal information provided across his other VKontakte profiles.

Source: vkwatch[.]com
A notable detail emerges from observing the various usernames Rudometov used over the years. One of his earliest usernames, navi_ghacking, was used to register his VKontakte account, while Dendimirror appeared in promotional images for his software he advertised through VKontakte group “Custom Software Writing” mentioned above.
The monikers Dendimirror, GHackiHG (likely a variation of navi_ghacking), and another alias, Alinchok, were later linked to MysteryStealer – an infostealer malware considered a predecessor of RedLine and likely one of Rudometov’s first significant illicit ventures. According to the indictment, investigators identified posts from 2017 on various Russian-language hacker forums and other publicly accessible websites where the moniker Dendimirror was used in connection with MysteryStealer. This discovery connected Rudometov’s early activities to his later, more sophisticated cybercriminal endeavors.

Source: VKontakte
Around the same time in 2017, monikers Dendimirror and Alinchok were observed on the VLMI forum, where two accounts were used to advertise the URI botnet (Universal Remote Installer). It remains unclear whether both accounts were operated solely by Rudometov or if another individual, whose identity has yet to be confirmed, was involved in the operation. Ironically, the profile description and stated date of birth on the Dendimirror account align with information stated by Rudometov across multiple identified accounts, including his VKontakte profiles – all listing his birthdate as March 21, 1999.

Source: VLMI forum
This pattern of reusing usernames suggests more than mere habit. It’s common for cybercriminals to retain their monikers over long periods to build credibility within the underground community. For Rudometov, however, these aliases appear to have deeper roots, stretching back to his early years, even before his involvement in illicit activities.
In his case, the clear attachment to these aliases potentially suggests more than a strategy for maintaining credibility, hinting at a profound psychological dimension. For some actors, these identities evolve into more than just a name – they become a persona, a psychological shield that allows them to operate in the shadows. This attachment can be so strong that it becomes difficult to let go, even when it increases the risk of exposure.
This lack of care in maintaining strict OPSEC (operational security) practices not only led to the exposure of his identity by law enforcement but also attracted unwanted attention within his circles – the underground community. For reasons that remain unclear, Rudometov’s illicit business sparked a backlash from some community members. In an effort to tarnish his reputation, several blogs and posts emerged, seeking to discredit his services and undermine his credibility.
One notable example was a blog post published by an individual using the alias LordOdin on Telegraph on February 26, 2019. In the post, LordOdin exposed flaws in MysteryStealer, criticizing its poor performance and reliability based on user feedback. However, the blog didn’t stop at technical critiques. It escalated to personal attacks, including the release of private information – or “doxing” – which included a real photo of Rudometov. In this photo, which appears to be another promotion of Rudometov’s services at some point, he advertises teaching the C# programming language, including botnet and infostealer development, using the previously known username Dendimirror as his identifier.

Source: Telegraph
Indeed, this is a prime example of the often-hostile environment within Russian-speaking cybercrime circles, where rivals quickly exploit any vulnerability to discredit and undermine one another. This competitive atmosphere serves as the greatest weakness and flaw, creating distrust that often contributes to the downfall of these actors. The internal competition inside of cybercriminal community and Rudometov’s attachment to his digital identity, evidenced by his reuse of monikers, ultimately aided law enforcement in unmasking him. After a lengthy investigation, by November 2022, the U.S. District Court for the Western District of Texas issued a warrant for Maxim Rudometov’s arrest. What were the main artifacts that allowed investigators to trace Rudometov? Let’s explore them in the next section.
The Power of a Multifaced Investigation Approach: The Downfall of Rudometov & What’s Next?
Multiple artifacts allowed law enforcement to build a case against Rudometov, including different types of evidence listed in an indictment. A combination of digital forensics and blockchain tracing of illicit funds obtained through crime played a pivotal role. Earlier this year, we published a case study on another conviction, showcasing this blended approach as a recipe for success in cybercrime investigations involving an individual engaged in Karakurt ransomware operations.
In Rudometov’s case, the same approach was applied. For instance, while using the “Dendimirror” moniker, a U.S. private security firm discovered an email address in a leaked database tied to an account on a Russian-language hacker forum using the same alias. This email address, provided by the Russian service Yandex and already known to law enforcement, was later connected to several online accounts linked to other monikers associated with Dendimirror, such as “GHackiHG” and “bloodzz.fenix”. Additionally, law enforcement traced repeated access to a single Yandex email address they had identified as being tied to Maxim Rudometov.
Furthermore, this Yandex email address was linked to services Rudometov personally used, including Google and Apple accounts, further solidifying the connection between his real identity and his digital aliases. According to the indictment, on May 2, 2021, an individual using an IP address ending in -.14 signed a malicious file via the licensing server. About an hour earlier, the same IP address was recorded logging into an Apple iCloud account belonging to Rudometov while playing a mobile game. The IP address was assigned to an Internet Service Provider in Krasnodar, Russia, and later connected to a Skype account used on hacker forums and to access a GitHub repository containing a known Windows exploit. In July 2021, this IP address accessed the iCloud account approximately 701 times.
Moreover, on May 16, 2021, a user named “Heijs,” using an IP address ending in -.180, requested a build of RedLine from the licensing server. About nine minutes later, Apple logged the same IP address as having accessed Maxim Rudometov’s iCloud account. Additional IP addresses tied to Rudometov’s online accounts also interacted with the RedLine licensing server under usernames like “Admin12” and “testpanel.”
Cryptocurrency transactions linked to Rudometov’s accounts revealed patterns consistent with RedLine licensing payments. This highlights the importance of integrating blockchain intelligence with digital forensics for investigation. In the case of RedLine’s operations, the blockchain data aligned with the pricing for RedLine services according to the rates advertised for its illicit services, including a subscription fee of $150 per month or a one-time payment of $900 in cryptocurrency. Several transactions matched these typical licensing fees, indicating revenue from selling the malware. Investigations confirmed that Rudometov received payments on his Binance account ending in -8286 and forwarded them to another account, believed to be used for obfuscating the funds.
The evidence has been presented, and the case is built – so when will Rudometov face justice? It is suspected that Rudometov’s place of birth was Luhansk, Ukraine, as indicated on his multiple VKontakte accounts. Below is an image of one of his VKontakte accounts, swiftly deleted the day after the indictment was announced. Based on the extracted history of the profile initial stated place of residence stated in 2013 as Luhansk, Ukraine, was eventually updated to Moscow, Russia, in 2021, suggesting that he may have relocated to Russia around that time.

Source: vkwatch[.]com
Rudometov’s potential residence in Russia was confirmed through an in-depth OSINT investigation conducted by OSINord – The Nordic OSINT Community, led by Ron Kaminsky and Valdemar J. Balle. The investigation uncovered multiple pieces of evidence pointing to Rudometov’s probable past and current residences while also providing insight into his lifestyle.
According to the findings, Rudometov previously lived in Luhansk, corroborating the information about his residence that he provided across multiple social media accounts. During his time there, he obtained a driver’s license from a local driving school, further validating his connection to the region.

Source: www[.]osinord[.]com
Further investigation revealed that Rudometov is now likely living in Krasnodar, Russia, where he maintains an extravagant lifestyle. This includes frequenting upscale nightclubs, bars, and restaurants, getting new tattoos, and keeping a large circle of friends and acquaintances. One of the most recent images below shows Rudometov at a restaurant, identified as one of the bars in Krasnodar, Russia.

Source: www[.]osinord[.]com
Rudometov’s likely move from Ukraine to Russia cannot be overlooked and requires a deeper understanding of the social and political processes in these regions, which have profoundly impacted the lives of their residents. His relocation to Russia may be explained by the socio-political events that have unfolded in the Luhansk region over the past decade.
Since 2014, the annexation of Crimea by Russia marked the beginning of heightened tensions, as the Donetsk and Luhansk regions of Ukraine became embroiled in a militia conflict with Russia attempting to assert control over them. Despite widespread international rejection, Russia has claimed four Ukrainian provinces – Crimea, Kharkiv, Luhansk, and Donetsk – as part of its territory.
On October 4, 2022, when the Luhansk People’s Republic was officially declared part of Russia, residents of Luhansk who had been permanently living in the region and their minor children were granted Russian citizenship. This strategic move was likely designed to consolidate Russian influence in the region and foster loyalty among the local population. According to the Russian state media RIA, nearly 80 percent of residents in the Luhansk and Donetsk regions, where Rudometov is likely originally from, hold Russian citizenship.
This widespread shift in legal and national identity reflects the deep entanglement of geopolitical strategy and individual lives in these contested areas, shaping the socio-political landscape in which Rudometov’s story unfolds. While the reasons behind Rudometov’s eventual relocation remain unclear; however, it appears to have been a strategic decision. Moving to Russia – a country known for its protective stance toward cybercriminals operating within its borders – offers significant advantages for someone engaging in illicit activities. Russia’s reluctance to extradite its citizens and its history of shielding cybercriminals from Western law enforcement make it an attractive haven for individuals involved in illegal activities.
Furthermore, the socio-political climate in Russia often fosters a sense of impunity for such actors, particularly when their activities target foreign adversaries rather than domestic interests. For his alleged activities, Rudometov faces charges of access device fraud, conspiracy to commit computer intrusion and money laundering. These charges are allegations, and Rudometov is presumed innocent until proven guilty. If convicted, however, he could face up to 35 years: 10 years for access device fraud, five years for conspiracy to commit computer intrusion, and 20 years for money laundering.
As this story unfolds, the question remains: will Rudometov ever face justice? Innocent until proven guilty, his ultimate fate may hinge on the direction of international relations between Russia and other countries, influenced by the prevailing political climate. Analyst1 continues to monitor RedLine’s activity and legal actions related to prosecuting individuals behind its operations.
About Analyst1
Threat intelligence teams often struggle to bridge the gap from insight to action. Analyst1 is the Orchestrated Threat Intelligence Platform designed to resolve this issue. It automatically organizes threat data, links it to your assets and vulnerabilities, and customizes views for different roles. Analyst1’s orchestration layer streamlines workflows and automates reliable actions by integrating with SIEM, ticketing, and vulnerability management systems. From Fortune 500 financial institutions to national security agencies, enterprises trust Analyst1 to unify their defenses, significantly reducing their response time from days to minutes.