logo

Fake LastPass, Bitwarden breach alerts lead to PC hijacks

ID: d5fbc523-84a3-5a31-8454-8ea03beab3f7

STIX ID: report--d5fbc523-84a3-5a31-8454-8ea03beab3f7

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-10-15

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

An ongoing phishing campaign impersonates LastPass and Bitwarden to trick users into downloading a fake "secure" desktop client; the distributed binary installs the Syncro MSP agent which is then used to deploy ScreenConnect remote-access software, hide the agent, disable some security agents, and enable remote access for follow-on malware and potential credential or vault theft. Cloudflare is blocking the malicious landing pages, and vendors (LastPass, Syncro) have stated they were not breached and have taken actions to block malicious accounts. Users are advised to ignore such emails and verify alerts through official vendor channels.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.