Desk live·
ForensicPost
Breaches/Enforcement/File 24-1028

Operation Magnus Dismantled RedLine and META and Seized the Customer List

Operation Magnus dismantled RedLine and META — two infostealers that between them had harvested hundreds of millions of credentials. Police seized not just the infrastructure but the registration details of the people renting it.

Constructed geometry · not a chart of case data
JurisdictionNetherlandsthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetRedLine and META users
ActorRegulator
S. Rosler13 min readConfidence: medium3 sources reviewed

On 28 October 2024 the Dutch National Police, working with the FBI, Eurojust and partners in the United Kingdom, Australia, Belgium and Portugal, announced Operation Magnus: the disruption of RedLine and META, two of the most widely rented information-stealing malware platforms in operation.

An infostealer is not ransomware. It does not announce itself. It runs once on a machine, empties the browser of saved passwords, session cookies and card details, sends them to a collection point and leaves. The victim usually never learns it happened.

What Makes This Takedown Different

Most disruptions seize servers. Reporting on Magnus describes law enforcement obtaining the source code, the REST API services, the licence servers, the stealer binaries and the Telegram bots — and, critically, the IP addresses, credentials and registration details of the customers.

These are malware-as-a-service products. The operators write and host; thousands of separate criminals rent. Seizing the licence server means seizing the customer database, which turns one takedown into a lead list — a materially different outcome from taking a botnet offline and watching it rebuild.

The Credential Figure Needs Its Label

Reporting has put the combined haul at over 451 million unique credentials, including cookies usable to bypass multi-factor authentication. That figure comes from the investigation and from vendor analysis of the seized material, not from an audited count, and this desk grades the file medium accordingly.

The cookie detail is the part that matters more than the number. A stolen password is defeated by a second factor. A stolen session cookie is the second factor already satisfied — it is proof that the check was passed, and replaying it skips the check entirely.

This is the closest thing the corpus has to a file on session hijacking, and it arrives sideways: not as an intrusion into one organisation, but as an industrial supply of pre-authenticated sessions sold by subscription.

Where The Victims Are In This

Nowhere, mostly. The people whose credentials sat in those databases were infected individually, months or years apart, usually through a cracked download or a malicious advertisement. There is no breached organisation to notify them, no regulator with jurisdiction over their laptop, and no incident number.

The corpus filed at 24-0413 that notification depends on an entity that still exists and can afford to write. Here there was never an entity at all. What the takedown produced instead was a check-your-exposure service — which is a real service, and which asks the affected person to come looking.

How we reported this

Compiled from law-enforcement announcements of Operation Magnus and contemporaneous reporting of them, listed below. The 451 million credential figure originates with the investigation and with vendor analysis of seized material; it is a count of records, not of distinct people, and is labelled as reported rather than established. The description of what was seized follows the announcements. This desk has not reviewed the seized material and makes no assessment of it. The account of how infostealers and session cookies work is general technique. Graded medium. Corrections: corrections@forensicpost.com.

Sources
  1. Operation Magnus targets RedLine, Meta infostealersCyberScoop
  2. Days after takedown, ESET Research releases analysis of the RedLine Stealer empireESET
  3. RedLine and META takedown: a turning point in the infostealer landscape?Flashpoint
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary