Target Industry
Indiscriminate, opportunistic targeting.
Overview
A new scam is targeting LastPass users, with threat actors posting fake five-star reviews on the Chrome Web Store to promote a fraudulent support number. LastPass is a password management tool that enables users to securely store, manage, and autofill their passwords.
It is designed to deceive LastPass users into calling a fraudulent support number. The number directs user to download malicious software, giving the threat actors remote access to the user’s devices and data. This is part of a larger campaign affecting users of various popular services.
Impact
The impact of the scam targeting LastPass users can be quite severe. Once the user has downloaded malicious software, it can lead to remote access to their devices and data. This may result in the theft of sensitive information and potential financial loss. The worst-case scenario may be compromised security.
Exploitation
This scam targeting LastPass users unfolds in four stages. First, threat actors post fake five-star reviews on the Chrome Web Store, which include a fraudulent support number. When a user calls this number, they are connected to the threat actors posing as legitimate support agents.
Next, the threat actor directs the user to a malicious website, tricking them into downloading harmful software. Once installed, this software grants the threat actor remote access to the user’s devices, allowing them to steal sensitive information and control the device. This scam is part of a broader campaign targeting users of various popular services, significantly increasing the risk of widespread impact.
Containment, Mitigations & Remediations
It is recommended only to use the official support channels listed on LastPass’s website. Never trust numbers found in reviews or forums. Avoid clicking on unfamiliar links or entering codes on untrusted websites.
Indicators of Compromise
The fake contact support number being used in this scam is 805–206–2892. The number has also been reported for companies like Amazon, Adobe, Facebook, Hulu, YouTube TV, Peacock TV, Verizon, Netflix, Roku, PayPal, Squarespace, Grammarly, iCloud, Ticketmaster, and Capital One.
The URL which users are directed to is dghelp[.]top along with a code given out by the threat actor to download a ConnectWise ScreenConnect agent. The ScreenConnect client is configured to connect to molatorimax[.]icu and n9back366[.]stream. These sites were previously linked to an IP address in Ukraine.
Threat Landscape
While LastPass currently dominates the password management industry, it could pose a critical threat to an organisation with unsuspecting users.
Threat Group
The specific threat group behind this scam has not been publicly identified.
TTPs
- T1005 – Data from Local System
- T1219 – Remote Access Software
- T1566 – Phishing
- T1072 – Software Deployment Tools
Further Information
https://cybersecuritynews.com/lastpass-hackers-misusing-reviews/
https://medium.com/@wiretor/lastpass-warns-of-fake-support-centers-targeting-users-3285be74ce8b













