HomeSecurityHave I Been Pwned: Added 441,000 accounts stolen by RedLine...

Have I Been Pwned: Added 441,000 accounts stolen by RedLine malware

Data breach notification service Have I Been Pwnednow lets you check if email and password are one of the 441,000 accounts that have been stolen by an information theft campaign using the RedLine malware.

Have I Been Pwned?

See also: RedLine malware: Passwords should not be saved in browsers

RedLine is currently the most widely used information-stealing malware, distributed through phishing campaigns with malicious attachments, YouTube scams, and warez/crack websites.

Once installed, RedLine will attempt to steal cookies, credentials, credit cards, and autofill information stored in browsers. It also steals credentials stored in VPN clients and FTP clients, steals cryptocurrency wallets, and can download additional software or execute commands on the infected system.

The stolen data is collected in a file, called “logs,” and sent to a remote server from where the attacker can later collect it.

Attackers use these logs to hack other accounts or sell them on Dark Web marketplaces for as little as $5 per file.

Last weekend, security researcher Bob Diachenko found a server exposing over 6 million RedLine logs collected in August and September 2021. The malicious actor likely used this server to store stolen data, but failed to properly secure it.

See also: Malicious Excel XLL add-ins promote RedLine malware

RedLine

Diachenko said that while this data contains 6 million records, many had the same email address used for different services.

This week, many LastPass users received emails warning that their master passwords might be compromised as they were being used to log in from an unusual location.

Diachenko found that many LastPass had been stolen and stored in the exposed RedLine logs, and he checked various emails for LastPass users who received the emails to see if they were listed.

Diachenko said the server is still accessible, but it no longer appears to be used by malicious actors, as the number of logs has not increased.

RedLine's data contains 441,657 unique email addresses that have been stolen and can now be searched on Have I Been Pwned.

See also: FBI will check compromised passwords on Have I Been Pwned

Unfortunately, if your email address is listed in the RedLine malware logs, it's not enough to simply change the passwords associated with that email account. You should scan your computer using antivirus software to detect and remove any installed malware.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS