Cyberattackers Target LastPass, Top Password Managers
ID: 71773fb8-5fef-5b1b-a21b-829332adea3c
STIX ID: report--71773fb8-5fef-5b1b-a21b-829332adea3c
Feed Name: Dark Reading
Multiple, active phishing campaigns are impersonating major password managers (1Password, LastPass, Bitwarden) to trick users into disclosing master passwords or downloading maliciously repackaged legitimate tools; one observed chain used a modified Syncro installer to deploy ScreenConnect RMM for remote access. These attacks pose high-impact risks because control of a master password can expose many accounts, and attackers leveraged social engineering and legitimate software to evade detection, while vendor-recommended MFA and additional protections can mitigate some risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
