Tag: password manager

Fake KeePass password manager leads to ESXi ransomware attack
News

Fake KeePass password manager leads to ESXi ransomware attack

For at least eight months, threat actors have been disseminating trojanized versions of the KeePass password manager in order to install Cobalt Strike beacons, harvest login credentials, and then infect the compromised network with ransomware. After being called in to look into a ransomware attack, WithSecure's Threat Intelligence team learned about the campaign. The researchers discovered that a malicious KeePass installer sent via Bing ads that promoted phony software websites was the initial step in the attack. Since KeePass is open source, the threat actors modified the source code to create a trojanized version called KeeLoader that has all of the features of a standard password manager. On the other hand, it contains changes that set up a Cobalt Strike beacon and export the Ke...