HomeSecurityRedLine malware: Passwords should not be stored in browsers

RedLine malware: Passwords should not be stored in browsers

RedLine information-stealing malware targets popular browsers like Chrome , Edge, and Opera, proving why storing passwords in browsers is a bad idea.

RedLine

See also: Flagpro: New malware linked to Chinese state hackers

This malware steals information and can be purchased for about $200 on cybercrime forums and deployed without requiring extensive knowledge or effort.

However, a new report from AhnLab ASEC warns that the ease of use of the automatic login feature in web browsers is becoming a significant security problem affecting both organizations and individual users.

In one example presented by analysts, a remote employee lost his VPN account credentials due to RedLine Stealer, with its operators using the information to hack the company's network three months later.

Even though the infected computer had protection software installed, it failed to detect and remove the RedLine Stealer.

The malicious software targets the “Login Data” file that is found in all browsers based on Chromium and is an SQLite database where usernames and passwords are stored.

See also: Mozilla Firefox: The first Chromium alternative in the Windows Store

Even when users refuse to store their credentials in the browser, the password management system will continue to add an entry indicating that the particular site is on the “blacklist”.

browser

Even though the malicious actor may not have the passwords for’ this account on the “blacklist”, it says that the account exists, allowing it to perform credential stuffing or social engineering/phishing attacks.

After they collect the stolen credentials, the hackers either use them in further attacks or try to generate revenue by selling them on Dark Web markets.

Another recent distribution case of RedLine is a spam campaign with a website contact form that uses Excel XLL files that download and install the malicious password‑stealing software.

It seems that RedLine is everywhere right now, and the main reason behind this is its effectiveness in exploiting a widely available security gap that modern web browsers cannot address.

The use of a web browser to store your login credentials is tempting and convenient, but it is also dangerous.

See also: DarkWatchman: New malware hides in the Windows Registry

Conversely, it would be better to use an exclusive password manager that stores everything in an encrypted “vault” and asks for the master password to unlock it.

Additionally, you should configure specific rules for sensitive sites, such as online banking portals or corporate asset websites, that require non‑automatic credential entry.

Finally, enable multi-factor authentication wherever it is available, as this additional step can save you from account takeover incidents, even if your credentials have been compromised.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS