Breaking
June 2, 2025

Hackers are distributing a cracked password manager that steals data, deploys ransomware | usagoldmines.com


  • A malicious variant of KeePass is being offered online
  • The malware deploys an infostealer and a Cobalt Strike beacon
  • The cybercriminals are using the access to deploy ransomware

Cybercriminals are distributing a tainted version of a popular password manager, through which they’re able to steal data and deploy ransomware. This is according to security researchers WithSecure Threat Intelligence, who recently observed one such attack in the wild.

In an in-depth analysis published recently, the researchers said a client of theirs downloaded what they thought was KeePass – a popular password manager. They clicked on an ad from the Bing advertising network, and landed on a page that looked exactly like the KeePass website.

The site, however, was a typosquatted version of the legitimate password manager. Since KeePass is open-source, the attackers kept all of the legitimate tool’s functionalities, but with a little extra Cobalt Strike on the side.

60% off for Techradar readers

With Aura’s parental control software, you can filter, block, and monitor websites and apps, set screen time limits. Parents will also receive breach alerts, Dark Web monitoring, VPN protection, and antivirus.

Preferred partner (What does this mean?)View Deal

Purview and Defender

The fake password manager exported all of the saved passwords in a cleartext database, which was later relayed to the attackers through the Cobalt Strike beacon. The attackers then used the login credentials to access the network and deploy ransomware, which is when WithSecure was brought in.

WithSecure said that the campaign has the fingerprints of an initial access broker (IAB), a type of hacking group that obtains access to organizations and then sells it to other hacking collectives. This particular group is most likely associated with Black Basta, an infamous ransomware operator, and is now being tracked as UNC4696.

This group was previously linked to Nitrogen Loader campaigns, BleepingComputer reported. Older Nitrogen campaigns were linked to the now defunct BlackCat/ALPHV group.

So far, this was the only observed attack, but that doesn’t mean there aren’t others, WithSecure warns: “We are not aware of any other incidents (ransomware or otherwise) using this Cobalt Strike beacon watermark – this does not mean it has not occurred.”

The typosquatted website that’s hosting the malicious KeePass version was still up and running at this time, and was still serving malware to unsuspecting users. In fact, WithSecure said that behind the site was extensive infrastructure, created to distribute all sorts of malware posing as legitimate tools.

Via BleepingComputer

You might also like

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Time’s up: Windows 10 support ends, but Windows 11 Pro is just $15 | usagoldmines.com

Why Apple TV Beats Roku and Fire TV for Privacy Protection Tim Hardwick | usagoldmines.com

The security debt of browsing AI agents | usagoldmines.com

Why hacking yourself first is essential for proactive cybersecurity | usagoldmines.com

Best VPN deals: Protect your privacy for the lowest prices | usagoldmines.com

Best PC computer deals: Top picks from desktops to all-in-ones | usagoldmines.com

Quantum computing startup wants to launch a 1000-qubit machine by 2031 that could make the tradition...

Seagate CEO hints at 150TB hard drives thanks to novel 15TB platters, but notes it won't happen for ...

Netflix drops Squid Game S3 trailer Jennifer Ouellette | usagoldmines.com

We may have some information on incoming smartwatches from Android phone and tablet maker HMD | usa...

WWDC 2025 Likely 'Smaller-Scale' Than Past Two WWDCs, Here's Why Joe Rossignol | usagoldmines.com

Instagram Expected to Release iPad App Later This Year Joe Rossignol | usagoldmines.com

InnoCN takes aim at Apple with an affordable 40-inch 5K ultrawide monitor with factory calibration a...

Get $100 Off Nearly Every M3 iPad Air on Amazon, Available From $499 Mitchel Broussard | usagoldmine...

macOS Tahoe Name Leaked Ahead of Apple's WWDC Event Next Week Joe Rossignol | usagoldmines.com

Sony WH-1000XM6 repairability report gives you another reason to buy these flagship headphones | us...

You can fit an SSD on this graphics card that has a USB Type-C connector, but I am not a fan of its ...

NYT Strands hints and answers for Monday, June 2 (game #456) | usagoldmines.com

NYT Connections hints and answers for Monday, June 2 (game #722) | usagoldmines.com

Quordle hints and answers for Monday, June 2 (game #1225) | usagoldmines.com

High Potential season 2: release window, cast and everything we know so far about the hit Hulu crime...

8 common Chromebook myths that simply aren’t true | usagoldmines.com

The Sage Barista Impress is so satisfying to use, I just want to make lattes all day | usagoldmines...

Breaking down why Apple TVs are privacy advocates’ go-to streaming device Scharon Harding | usagoldm...

New PC? Make it easy with this $35 transfer bundle. | usagoldmines.com

All-in-one project control for just $15 | usagoldmines.com

I’m an iOS loyalist – here’s why Android has never tempted me to switch alexblake.techradar@gmail.co...

Netflix Tudum 2025 live: the biggest news about Stranger Things, One Piece, Squid Game and more amel...

Criminals hijacking subdomains of popular websites such as Bose or Panasonic to infect victims with ...

Research roundup: 7 stories we almost missed Jennifer Ouellette | usagoldmines.com

Trump pulls Isaacman nomination for space. Source: “NASA is f****ed” Eric Berger | usagoldmines.com

Everything new on Paramount+ in June 2025 – including over 80 new movies to add to your watchlist ro...

Seagate confirms 40TB hard drives have already been shipped, but don't expect them to go on sale any...

I slapped this $30 LED strip on the back of my TV. My eyes thank me daily | usagoldmines.com

Cybercriminals are deploying deepfake sentinels to test detection systems of businesses: here's what...

Sonos Father's Day Sale Introduces Big Discounts on Arc Ultra Soundbar and More Mitchel Broussard | ...

Apple is rumored to be working on haptic buttons for the iPhone, iPad, and Apple Watch | usagoldmin...

NYT Strands hints and answers for Sunday, June 1 (game #455) | usagoldmines.com

Quordle hints and answers for Sunday, June 1 (game #1224) | usagoldmines.com

NYT Connections hints and answers for Sunday, June 1 (game #721) | usagoldmines.com

Everything new on Max in June 2025 – catch season 3 of The Gilded Age and over 60 new movies rowan.d...

Ransomware kingpin “Stern” apparently IDed by German law enforcement Lily Hay Newman, wired.com | us...

Top Stories: iOS 26 Incoming?, iPhone 17 Pro Rumors, and More MacRumors Staff | usagoldmines.com

Supergirl: Woman of Tomorrow – release date, confirmed cast, plot details, and more about the exciti...

Champions League Final: LIVE: stream, PSG vs Inter team news, all the build-up from Munich | usagol...

Samsung’s tiny-yet-fast USB-C flash drive is only $18 right now | usagoldmines.com

This AI platform claims to 'understand' human emotions and sense stress and anxiety: here's what you...

Real TikTokers are pretending to be Veo 3 AI creations for fun, attention Kyle Orland | usagoldmines...

The Samsung Galaxy S25 Edge might look gorgeous, but its headline feature stands out for all the wro...

We just got a big hint that the Google Pixel 10 could be launching earlier than expected | usagoldm...

Got the Sony WH-1000XM4? Here’s 3 reasons I’d upgrade to the Sony WH-1000XM6 after testing them side...

Practical Magic 2: release date, cast and everything we know about the spellbinding sequel | usagol...

Don’t miss this sale—a MacBook Air for just $199.97 | usagoldmines.com

AI powering a “dramatic surge” in cyberthreats as automated scans hit 36,000 per second | usagoldmi...

ICYMI: the 8 biggest tech stories of the week, from Google's new AI video magic to WhatsApp on the i...

No One Is Buying Phones for AI Jake Peterson | usagoldmines.com

‘Mission: Impossible – The Final Reckoning’ gets surprise guest appearance: a revolutionary 360TB si...

You Can Get a Lifetime License to Qlango for Just $35 Right Now Pradershika Sharma | usagoldmines.co...

Galaxy S22 Series, Others Get May Security Patch Tim | usagoldmines.com

6 visionOS-Inspired Design Elements Coming to iOS 26 Juli Clover | usagoldmines.com

This movie is fully AI-generated and has a fully SAG-AFTRA cast – here’s 3 things you need to know a...

Google and DOJ tussle over how AI will remake the web in antitrust closing arguments Ryan Whitwam | ...

WordPad is dead in Windows 11, but Notepad is absorbing its skills | usagoldmines.com

A Four Pack of These TSA-Approved SmartLocks Is $80 Right Now Pradershika Sharma | usagoldmines.com

Some data centers are deliberately slowing possibly tens of thousands of AI GPUs to avoid blackouts ...

Superfast 32TB USB4 External SSDs are coming, thanks to a new chip - but I bet they won't be cheap ...

CDC updates COVID vaccine recommendations, but not how RFK Jr. wanted Beth Mole | usagoldmines.com

Amazon Fire Sticks enable “billions of dollars” worth of streaming piracy Scharon Harding | usagoldm...

Gmail Will Automatically Summarize Your Emails Using Gemini AI (but You Can Disable It) Khamosh Path...

Spy-catcher saw “stupid” tech errors others made. FBI says he then made his own. Nate Anderson | usa...

You Can Get This Budget Lenovo Chromebook for Just $55 Right Now Pradershika Sharma | usagoldmines.c...

I Use These Sites to Track All the Collectibles in My Games Eric Ravenscraft | usagoldmines.com

Texas’s New App Store Age Verification Law Has Serious Privacy Issues Emily Long | usagoldmines.com

iPhone 17 With a Smaller Dynamic Island? Here's What Rumors Say Joe Rossignol | usagoldmines.com

Want to carry an Nvidia GeForce RTX 5090 to your laptop? Here's an eGPU chassis that should do the t...

Devious new ClickFix malware variant targets macOS, Android, and iOS using browser-based redirection...

Why incels take the “Blackpill”—and why we should care Jennifer Ouellette | usagoldmines.com

Want a humanoid, open source robot for just $3,000? Hugging Face is on it. Samuel Axon | usagoldmine...

Texas AG loses appeal to seize evidence for Elon Musk’s ad boycott fight Ashley Belanger | usagoldmi...

LG’s 34-inch ultrawide OLED gaming monitor just hit its lowest price | usagoldmines.com

Acer’s Copilot+ OLED laptop is a bargain now that it’s $400 off | usagoldmines.com

Today, Microsoft Edge Game Assist. Tomorrow, a Windows AI game buddy | usagoldmines.com

This fantasy Borderlands spin-off is free right now! Grab it before it ends | usagoldmines.com

DEAL: Galaxy Watch Ultra is $200 Off, Only $324 With Trade-in Tim | usagoldmines.com

I Trained My YouTube Algorithm, and You Should Too Eric Ravenscraft | usagoldmines.com

Six Tricks Companies Use to Hide the Impact of Tariffs Jeff Somers | usagoldmines.com

My Favorite Amazon Deal of the Day: The Sonos Arc Ultra Soundbar Daniel Oropeza | usagoldmines.com

If You Have an Asus Router, You Need to Check If It's Been Hacked Jake Peterson | usagoldmines.com

iPhone 17 Base Model Now Said to Feature A18 Chip and 8GB of RAM Joe Rossignol | usagoldmines.com

It’s official, Android users: Instagram is draining your battery, but there's now a fix | usagoldmi...

After Supreme Court loss, ISPs ask Trump admin to block state affordability laws Jon Brodkin | usago...

NASA robot for drilling on icy moons tested on Alaskan glacier Jacek Krywko | usagoldmines.com

Blink Sync Module XR review: Network storage on a budget | usagoldmines.com

You Can Get This iPhone 12 on Sale for $230 Right Now Pradershika Sharma | usagoldmines.com

Apple Shares 2024 App Store Data: Rejections, Removals, and More Juli Clover | usagoldmines.com

MacRumors Giveaway: Win an iPhone 16 Pro From Digiarty VideoProc Juli Clover | usagoldmines.com

This worrying Apple Safari security bug could leave users wide open to cyberattacks | usagoldmines....

Billions of stolen cookies are still for sale on the internet - here's how to stay safe | usagoldmi...

The Gmail app will now create AI summaries whether you want them or not Ryan Whitwam | usagoldmines....

I made one small tweak to my gaming PC. The payoff has been huge | usagoldmines.com