Target Industry

Indiscriminate, opportunistic targeting.

Overview

A new scam is targeting LastPass users, with threat actors posting fake five-star reviews on the Chrome Web Store to promote a fraudulent support number. LastPass is a password management tool that enables users to securely store, manage, and autofill their passwords.

It is designed to deceive LastPass users into calling a fraudulent support number. The number directs user to download malicious software, giving the threat actors remote access to the user’s devices and data. This is part of a larger campaign affecting users of various popular services.

Impact

The impact of the scam targeting LastPass users can be quite severe. Once the user has downloaded malicious software, it can lead to remote access to their devices and data. This may result in the theft of sensitive information and potential financial loss. The worst-case scenario may be compromised security.

Exploitation

This scam targeting LastPass users unfolds in four stages. First, threat actors post fake five-star reviews on the Chrome Web Store, which include a fraudulent support number. When a user calls this number, they are connected to the threat actors posing as legitimate support agents.

Next, the threat actor directs the user to a malicious website, tricking them into downloading harmful software. Once installed, this software grants the threat actor remote access to the user’s devices, allowing them to steal sensitive information and control the device. This scam is part of a broader campaign targeting users of various popular services, significantly increasing the risk of widespread impact.

Containment, Mitigations & Remediations

It is recommended only to use the official support channels listed on LastPass’s website. Never trust numbers found in reviews or forums. Avoid clicking on unfamiliar links or entering codes on untrusted websites.

Indicators of Compromise

The fake contact support number being used in this scam is 805–206–2892. The number has also been reported for companies like Amazon, Adobe, Facebook, Hulu, YouTube TV, Peacock TV, Verizon, Netflix, Roku, PayPal, Squarespace, Grammarly, iCloud, Ticketmaster, and Capital One.

The URL which users are directed to is dghelp[.]top along with a code given out by the threat actor to download a ConnectWise ScreenConnect agent. The ScreenConnect client is configured to connect to molatorimax[.]icu and n9back366[.]stream. These sites were previously linked to an IP address in Ukraine.

Threat Landscape

While LastPass currently dominates the password management industry, it could pose a critical threat to an organisation with unsuspecting users.

Threat Group

The specific threat group behind this scam has not been publicly identified.

TTPs 

  • T1005 – Data from Local System 
  • T1219 – Remote Access Software 
  • T1072 – Software Deployment Tools 

Further Information 

https://cybersecuritynews.com/lastpass-hackers-misusing-reviews/ 

https://medium.com/@wiretor/lastpass-warns-of-fake-support-centers-targeting-users-3285be74ce8b 

https://www.bleepingcomputer.com/news/security/lastpass-warns-of-fake-support-centers-trying-to-steal-customer-data/?utm_source=dlvr.it&utm_medium=mastodon 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content