Close Menu
TechurzTechurz
    What's Hot

    Future of Digital Privacy and Security: 7 Truths Nobody Tells You

    May 25, 2026

    SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws major VC interest

    May 23, 2026

    Peec, one of Berlin’s rising startups, more than doubled annualized revenue in months to $10M, sources say

    May 23, 2026
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Tech Pulse
    • Future of Digital Privacy and Security: 7 Truths Nobody Tells You
    • SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws major VC interest
    • Peec, one of Berlin’s rising startups, more than doubled annualized revenue in months to $10M, sources say
    • This young startup is taking on a fragrance industry that hasn’t changed in a almost half century
    • Maka Kids is redefining kids’ screen time with a streaming app optimized for well-being, not engagement
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    TechurzTechurz
    • Home
    • Tech Pulse
    • Future Tech
    • AI Systems
    • Cyber Reality
    • Disruption Lab
    • Signals
    TechurzTechurz
    Home - Guides - This Fake Password Manager Reminds You to Watch Where You Download From
    Guides

    This Fake Password Manager Reminds You to Watch Where You Download From

    TechurzBy TechurzMay 21, 2025Updated:May 12, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    This Fake Password Manager Reminds You to Watch Where You Download From
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Downloading programs is an easy enough task, but only if you’re using official websites or app stores. If you use third-party sources or torrents, this fake password manager is a good reminder of why the official sources are best.

    This Password Manager Steals Your Passwords

    Security researchers at WithSecure have discovered a malware campaign in which hackers have been delivering trojanized versions of the KeePass password manager since at least October 2024. These versions install malware called Cobalt Strike along with the password manager, which can steal saved passwords and other credentials from your PC and deploy ransomware on your network.

    Since KeePass is open source, hackers easily accessed the source code to create a convincing clone. This malicious version is called KeeLoader and contains all of KeePass’ functionality, except it saves all your passwords as a text file and sends them to hackers using Cobalt Strike beacons.

    The distribution is handled by fake websites that use typo-squatted domains like the following:

    • keeppaswrd.com
    • keegass.com
    • KeePass.me
    • keespass.biz
    • keebass.com
    • KeePassx.com

    Some of these domains are still active and distributing fake versions of KeePass. For context, the legitimate KeePass website is at keepass.info. The fake websites were available via Microsoft’s Bing search engine. WithSecure claims that the fake domains were being served through DuckDuckGo advertisements. However, given that Microsoft and DuckDuckGo have formed a partnership on Microsoft-provided ads, it’s also likely that they were advertised with Bing as well.

    The entire campaign came to light during WithSecure’s investigation of a ransomware incident at a European IT service provider. It turned out that the fake password manager not only stole credentials but also installed ransomware on the company’s VMware ESXi servers. WithSecure noted that this is the first instance of an open-source password manager being used simultaneously as a credential-stealing tool and malware loader.

    Watch Where You Get Your Programs

    You can use your browser’s password manager with precautions, but using a dedicated program is a much more secure alternative. Hackers target password managers for exactly this reason—it puts risk where you least expect it, meaning they can catch you off guard.

    Related

    Don’t Fall for This Master Password Reset Email

    1Password users are under attack, but it’s relatively simple to keep your account safe.

    You should always download all programs, especially sensitive ones like your password manager, from their official websites or the app store based on your platform. Downloading software and games from third-party websites or torrents always runs the risk of your program coming with a side of malware.

    As an added precaution, I’d also recommend you avoid clicking on ads and sponsored links that encourage you to download a program. Even if the ad shows the legitimate URL for the program, hackers have repeatedly shown that they can bypass ad policies and display legitimate URLs while still redirecting you to fake sites.

    Download Fake manager Password Reminds Watch
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleWe tried on Google’s prototype AI smart glasses
    Next Article MSI’s component showcase at Computex was impressive, but in the end, I fell in love with a bracket
    Techurz
    • Website

    Related Posts

    Opinion

    Beyond Lovable and Mistral: 21 European startups to watch

    May 2, 2026
    Opinion

    Delve whistleblower strikes again, with alleged receipts about ‘fake compliance’

    March 31, 2026
    Opinion

    Insight Partners scrubs investment post about Delve amid ‘fake compliance’ allegations

    March 24, 2026
    Add A Comment
    Latest Tech Pulse

    College social app Fizz expands into grocery delivery

    September 3, 20252,289

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202517

    SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws major VC interest

    May 23, 202614
    Stay In Touch
    • YouTube
    • WhatsApp
    • Twitter
    • Pinterest
    • LinkedIn

    Techurz helps readers stay ahead of digital change with clear, practical, future-focused technology intelligence - written today, searched tomorrow.

    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Company
    • About Us
    • Contact Us
    • Our Authors / Editorial Team
    • Write For Us
    • Advertise
    Policy
    • Editorial Policy
    • Privacy Policy
    • Terms and Conditions
    • Affiliate Disclosure
    • Cookie Policy
    • Disclaimer
    • DMCA
    Explore
    • AI Systems
    • Cyber Reality
    • Future Tech
    • Disruption Lab
    • Signals
    • Tech Pulse
    • Sitemap

    Join the Techurz Brief

    The future does not arrive suddenly.
    Stay ahead with fast, sharp tech signals.

    Type above and press Enter to search. Press Esc to cancel.