There are a lot of users still using KeePass for various reasons. A common one is people "don't trust the cloud" to store passwords.
If that’s a comment referring to my “pretty rare style, for the 2020s,” a clarification. It’s not the target (KeePass) that is rare, but the attack style itself.
When it comes to data exfiltration and unauthorized access/use attacks, nowadays it’s usually hit-and-run tactics. Break in, grab whatever you can, disappear; or use to maximum extent until detected and then disappear. The entire attack takes under a second, maybe minutes. Resource use attacks may last days or weeks, until detection, but in this case the adversary just gets lucky; the assumption would still be hours at most.
Whereas this case of data exfiltration involves dormant malware waiting for the opportunity weeks or months. In this sense it’s rare. Kind of “old style.”