Cybercriminals pose as LastPass staff to hack password vaults
ID: 2c94c143-0f4c-5f5b-b37e-7fa6006ada71
STIX ID: report--2c94c143-0f4c-5f5b-b37e-7fa6006ada71
Feed Name: Bleeping Computer
Threat Score
LastPass warns of an active CryptoChameleon phishing campaign that uses voice phishing (vishing), spoofed support calls, and fake LastPass/SAML/Okta pages to harvest master passwords and take over password vaults; researchers observed the kit targeting cryptocurrency platforms and government employees, with indicators including the domain "help-lastpass.com" and email subject lines like "We're here for you."
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
