Do you use 1Password, LastPass, NordPass, or any other password manager? You're not alone. According to a 2023 Security.org study, roughly one in three people use a password manager to secure their login information. Password managers make logging in to your apps, social media accounts, and other online services easy.
They're also increasingly being targeted by cybercriminals.
According to a new report from cybersecurity firm Picus Security, cyberattacks on password managers and similar services, such as browser-stored credentials, have tripled compared to the previous year. The firm detailed these findings in its Red Report 2025.
SEE ALSO: Cybersecurity researchers discovered a scary security flaw with YouTube and GoogleResearchers found that out of more than a million malware variants, 25 percent of all malware targeted password managers or other credential storage services.
"For the first time ever, stealing credentials from password stores is in the top 10 techniques listed in the MITRE ATT&CK Framework," Picus Security said, referencing an industry framework for classifying cyberattacks.
According to Picus, cybercriminals are increasingly deploying multi-stage attacks, which the firm's researchers have dubbed "SneakThief." SneakThief describes a new type of malware attack that involves "increased stealth, persistence, and automation." These new malware attacks contain dozens of "malicious actions," which aid the hacker in gaining access and exporting data without getting caught.
SEE ALSO: How to spot and avoid the E-ZPass scam texts everyone's gettingWith so many apps and online platforms to manage logins for, more internet users have adopted password storage utilities to help manage them all. But, in turn, hackers have adjusted their malicious campaigns to shift their focus towards password managers. And it makes sense. Why would a hacker put their time and effort into stealing a target's login credentials to just one service when they could steal all their login credentials? Why steal a key to open just one door when you can take the master key and access everything?
"Threat actors are leveraging sophisticated extraction methods, including memory scraping, registry harvesting, and compromising local and cloud-based password stores, to obtain credentials that give attackers the keys to the kingdom," said Picus Security co-founder and VP of Picus Labs, Dr. Suleyman Ozarslan. "It’s vital that password managers are used in tandem with multi-factor authentication and that employees never reuse a password, especially for their password manager."
文章
61865
浏览
1
获赞
52
Prince Harry is 'over the moon' after Meghan Markle gives birth to a baby boy
The royal family has officially welcomed a new member.On Monday, the @sussexroyal Instagram accountBran Stark is a creep, and here are the memes to back it up
Warning: This post contains spoilers for Game of Thrones: Season 8, Episode 1I think we can all admiGoogle is thinking about a foldable Pixel, but don't expect it soon
Does the world really need foldable phones?If you ask Google Pixel development lead Mario Queiroz, tChrissy Teigen's daughter is now a meme, of course
You could argue that Chrissy Teigen is most well-known for being a personality who is constantly phoGoogle's Pixel 4a may have been delayed yet again
Google's cheaper Pixel phone is coming a bit later than originally anticipated. According to leakerSamsung delays the U.S. release of Galaxy Fold after screen problems
UPDATE: April 22, 2019, 1:07 p.m. ET: This story was updated to include the news that Samsung confirDesktop vs. Laptop Gaming with the RTX 2070
Since the launch of Nvidia's RTX GPUs we've been intrigued about the performance difference betweenAm I the only one who masturbates to podcasts? A look into audio porn.
May is National Masturbation Month, and we're celebrating with Feeling Yourself, a series exploringThese coronavirus trackers can help you sort through the info overload
If you're like me, the daily barrage of information about the progress of the coronavirus pandemic cElon Musk and Vitalik Buterin are chatting about Ethereum on Twitter
It's no surprise that Tesla & SpaceX CEO Elon Musk is interested in crypto -- he's tweeted aboutDo something good for Earth Day: Change how you get around
Last month, at an event to show off Tesla's newest electric car, CEO Elon Musk proclaimed, "This isHuawei's phone sales grew big time as Apple and Samsung's declined
Even without selling phones in the U.S., Chinese tech titan Huawei is well on its way to becoming thBitcoin wipes coronavirus losses, passes $10,000 again
There's a popular meme that shows Bitcoin on a perpetual rollercoaster. It's true: The world's largeDesktop vs. Laptop Gaming with the RTX 2070
Since the launch of Nvidia's RTX GPUs we've been intrigued about the performance difference betweenNo one noticed, but Uber and Lyft stopped accepting new NYC drivers
New wannabe Lyft and Uber drivers are out of luck in New York City.Both ride-hailing apps stopped ta