RedLine information-stealing malware targets popular browsers like Chrome , Edge, and Opera, proving why storing passwords in browsers is a bad idea.

See also: Flagpro: New malware linked to Chinese state hackers
This malware steals information and can be purchased for about $200 on cybercrime forums and deployed without requiring extensive knowledge or effort.
However, a new report from AhnLab ASEC warns that the ease of use of the automatic login feature in web browsers is becoming a significant security problem affecting both organizations and individual users.
In one example presented by analysts, a remote employee lost his VPN account credentials due to RedLine Stealer, with its operators using the information to hack the company's network three months later.
Even though the infected computer had protection software installed, it failed to detect and remove the RedLine Stealer.
The malicious software targets the “Login Data” file that is found in all browsers based on Chromium and is an SQLite database where usernames and passwords are stored.
See also: Mozilla Firefox: The first Chromium alternative in the Windows Store
Even when users refuse to store their credentials in the browser, the password management system will continue to add an entry indicating that the particular site is on the “blacklist”.

Even though the malicious actor may not have the passwords for’ this account on the “blacklist”, it says that the account exists, allowing it to perform credential stuffing or social engineering/phishing attacks.
After they collect the stolen credentials, the hackers either use them in further attacks or try to generate revenue by selling them on Dark Web markets.
Another recent distribution case of RedLine is a spam campaign with a website contact form that uses Excel XLL files that download and install the malicious password‑stealing software.
It seems that RedLine is everywhere right now, and the main reason behind this is its effectiveness in exploiting a widely available security gap that modern web browsers cannot address.
The use of a web browser to store your login credentials is tempting and convenient, but it is also dangerous.
See also: DarkWatchman: New malware hides in the Windows Registry
Conversely, it would be better to use an exclusive password manager that stores everything in an encrypted “vault” and asks for the master password to unlock it.
Additionally, you should configure specific rules for sensitive sites, such as online banking portals or corporate asset websites, that require non‑automatic credential entry.
Finally, enable multi-factor authentication wherever it is available, as this additional step can save you from account takeover incidents, even if your credentials have been compromised.
