Author Topic: KeePass: a long-running phishing attack  (Read 1175 times)

0 Members and 1 Guest are viewing this topic.

Offline golden_labelsTopic starter

  • Super Contributor
  • ***
  • Posts: 2441
  • Country: pl
KeePass: a long-running phishing attack
« on: May 16, 2025, 03:00:10 am »
WithSecure’s incident response team uncovered a long-running phishing atack against KeePass users: press release from WithSecurefull report (PDF).

tl;dr. The victim downloads a fake installer, which installs a slightly modified version of KeePass. It works like normal KeePass, until a database file is loaded into KeePass. At this point, and only in that scenario, it makes a plaintext copy of the database and drops a trojan to provide access.

A pretty rare style, for the 2020s.
Why 📎 | We live in times when half of people have IQ below 100.
 

Offline Halcyon

  • Global Moderator
  • *****
  • Posts: 6804
  • Country: au
Re: KeePass: a long-running phishing attack
« Reply #1 on: May 16, 2025, 03:04:31 am »
There are a lot of users still using KeePass for various reasons. A common one is people "don't trust the cloud" to store passwords.
 

Offline golden_labelsTopic starter

  • Super Contributor
  • ***
  • Posts: 2441
  • Country: pl
Re: KeePass: a long-running phishing attack
« Reply #2 on: May 16, 2025, 05:16:45 am »
There are a lot of users still using KeePass for various reasons. A common one is people "don't trust the cloud" to store passwords.
If that’s a comment referring to my “pretty rare style, for the 2020s,” a clarification. It’s not the target (KeePass) that is rare, but the attack style itself.

When it comes to data exfiltration and unauthorized access/use attacks, nowadays it’s usually hit-and-run tactics. Break in, grab whatever you can, disappear; or use to maximum extent until detected and then disappear. The entire attack takes under a second, maybe minutes. Resource use attacks may last days or weeks, until detection, but in this case the adversary just gets lucky; the assumption would still be hours at most.

Whereas this case of data exfiltration involves dormant malware waiting for the opportunity weeks or months. In this sense it’s rare. Kind of “old style.”
Why 📎 | We live in times when half of people have IQ below 100.
 

Offline bingo600

  • Super Contributor
  • ***
  • Posts: 2315
  • Country: dk
Re: KeePass: a long-running phishing attack
« Reply #3 on: May 16, 2025, 11:55:39 am »
Isn't this an "old" attack form ?

I'm quite sure that i enabled some Keepass warning, about saving the db in cleartext.
Tat advice was in a previous (year+) old warning, about the same stuff.

 


Share me

Digg  Facebook  SlashDot  Delicious  Technorati  Twitter  Google  Yahoo
Smf