LastPass users beware: Hackers exploit human weaknesses to challenge password manager security

LastPass users beware: Hackers exploit human weaknesses to challenge password manager security


Password manager LastPass has warned its users about a new phishing attack launched by the hacker group CryptoChameleon.

The media outlet reports that the attack dates back to mid-October. The attackers exploited LastPass's "Emergency Access" feature to send emails to users, falsely claiming that a family member had uploaded a death certificate and requesting access to their password vault.

To enhance credibility, the emails even included a fake agent ID number and instructed the recipient to click a link to cancel the request if they were still alive, luring users into the trap.

Clicking the link in the email redirected users to a fraudulent website called lastpassrecovery[.]com. This website, which mimics the official LastPass login page, asked users to enter their master password. Once the user entered and submitted their master password, the attackers compromised their entire password vault.

LastPass also noted that in some cases, attackers even proactively called victims, impersonating LastPass employees and directing them to enter their credentials on phishing websites, a double-edged attack.

Compared to the attacks launched by the group in April of this year, this campaign is both more widespread and more sophisticated. A key upgrade is that the attackers' targets have expanded from traditional passwords to include passkeys.

LastPass discovered that CryptoChameleon used phishing domains specifically targeting passkeys, such as mypasskey[.]info and passkeysetup[.]com. This suggests that as mainstream password managers began supporting and syncing passkeys, hackers have quickly adapted their strategies to directly target this perceived more secure passwordless authentication technology.

IT Home, citing a blog post, stated that CryptoChameleon (also known as UNC5356), the group behind this attack, is a financially motivated threat group specializing in stealing cryptocurrency using phishing kits. The organization has successfully attacked users of multiple cryptocurrency platforms such as Binance and Coinbase by forging login pages of well-known services such as Okta, Gmail, and iCloud.

New battery anode can withstand 2,100 cycles without wear and tear

South Korean scientists have proposed a new battery solution that could significantly extend the lifespan of electric vehicles and smartphones. This novel ano

New battery anode can withstand 2,100 cycles without wear and tear

Toyota pledges to launch an electric car with solid-state batteries by 2027

A Japanese company has announced it will launch the world's first electric vehicle equipped with solid-state batteries in 2027. This technology promises f

Toyota pledges to launch an electric car with solid-state batteries by 2027

Batteries powered by B vitamins and sugar could power electronic devices

Scientists have developed the world's first battery powered by vitamin B2 and glucose. It's based on the same principles the human body uses to conver

Batteries powered by B vitamins and sugar could power electronic devices

Artificial leaves mimic real photosynthesis

Scientists at the University of Cambridge have invented a "semi-synthetic leaf" that mimics photosynthesis, converting sunlight, water, and carbon dioxide int

Artificial leaves mimic real photosynthesis

BMW unveils its first self-inflating electric stand-up paddle board

BMW has unveiled its first self-inflating electric stand-up paddle board. This new product was developed in collaboration with Slovenian manufacturer SipaBoar

BMW unveils its first self-inflating electric stand-up paddle board

New Captery AA batteries charge in 160 seconds

Italian startup Captery has unveiled a rechargeable battery that charges in less than three minutes and lasts for decades. The company claims its technology wi

New Captery AA batteries charge in 160 seconds

The Prima eye implant restores vision to people.

Blind patients in the UK may be able to regain their reading ability with a new implant placed under the eye. Surgeons at London's Moorfields Hospital have

The Prima eye implant restores vision to people.

NASA plans to build a glass city on the moon

NASA is supporting an ambitious project aimed at enabling future human landings on the Moon. Skyeports, an American company, proposes building giant, transpar

NASA plans to build a glass city on the moon

Kohler launches smart toilet camera for health monitoring

Kohler, an American company known for its plumbing and kitchen appliances, has unveiled an unusual new product: the Dekoda camera. It attaches directly to the

Kohler launches smart toilet camera for health monitoring

LEDs can kill up to 92% of cancer cells

Scientists have developed a new light therapy that can destroy cancer cells without harming healthy cells. The method, which utilizes LEDs and tin nanosheets,

LEDs can kill up to 92% of cancer cells

New microturbine can operate on light winds

German engineers have invented a compact wind turbine that generates 83% more electricity than existing turbines of similar size. This invention could become

New microturbine can operate on light winds

The first fully recyclable electronic product has been created

Duke University researchers have developed a technology that could revolutionize the way displays are produced, even making them more environmentally friendly

The first fully recyclable electronic product has been created

Study: Neural networks speed up thinking but hinder deep analysis

Researchers at the University of Oxford have discovered how the use of neural networks affects students' cognitive functions. The so-called AI generation

Study: Neural networks speed up thinking but hinder deep analysis

Jason Schreier: Microsoft demands unattainable profits from Xbox

Bloomberg reporter Jason Schreier has once again exposed the hidden handcuffs in the gaming industry—this time, the focus is on Microsoft. It seems fans

Jason Schreier: Microsoft demands unattainable profits from Xbox

Bang & Olufsen has released a commemorative audio collection to mark the brand's 100th anniversary.

To celebrate its centennial, Danish brand Bang & Olufsen released special editions of its Beoplay H100 headphones and A9 and A5 speakers, dubbed the "Centenni

Bang & Olufsen has released a commemorative audio collection to mark the brand's 100th anniversary.