Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    This Sequoia-backed lab thinks the brain is ‘the floor, not the ceiling’ for AI

    February 10, 2026

    Primary Ventures raises healthy $625M Fund V to focus on seed investing

    February 10, 2026

    Vega raises $120M Series B to rethink how enterprises detect cyber threats

    February 10, 2026
    Facebook X (Twitter) Instagram
    Trending
    • This Sequoia-backed lab thinks the brain is ‘the floor, not the ceiling’ for AI
    • Primary Ventures raises healthy $625M Fund V to focus on seed investing
    • Vega raises $120M Series B to rethink how enterprises detect cyber threats
    • Former Tesla product manager wants to make luxury goods impossible to fake, starting with a chip
    • Former GitHub CEO raises record $60M dev tool seed round at $300M valuation
    • Hauler Hero collects $16M for its AI waste management software
    • Proptech startup Smart Bricks raises $5 million pre-seed led by a16z
    • Databricks CEO says SaaS isn’t dead, but AI will soon make it irrelevant
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Guides»This Fake Password Manager Reminds You to Watch Where You Download From
    Guides

    This Fake Password Manager Reminds You to Watch Where You Download From

    TechurzBy TechurzMay 21, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    This Fake Password Manager Reminds You to Watch Where You Download From
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Downloading programs is an easy enough task, but only if you’re using official websites or app stores. If you use third-party sources or torrents, this fake password manager is a good reminder of why the official sources are best.

    This Password Manager Steals Your Passwords

    Security researchers at WithSecure have discovered a malware campaign in which hackers have been delivering trojanized versions of the KeePass password manager since at least October 2024. These versions install malware called Cobalt Strike along with the password manager, which can steal saved passwords and other credentials from your PC and deploy ransomware on your network.

    Since KeePass is open source, hackers easily accessed the source code to create a convincing clone. This malicious version is called KeeLoader and contains all of KeePass’ functionality, except it saves all your passwords as a text file and sends them to hackers using Cobalt Strike beacons.

    The distribution is handled by fake websites that use typo-squatted domains like the following:

    • keeppaswrd.com
    • keegass.com
    • KeePass.me
    • keespass.biz
    • keebass.com
    • KeePassx.com

    Some of these domains are still active and distributing fake versions of KeePass. For context, the legitimate KeePass website is at keepass.info. The fake websites were available via Microsoft’s Bing search engine. WithSecure claims that the fake domains were being served through DuckDuckGo advertisements. However, given that Microsoft and DuckDuckGo have formed a partnership on Microsoft-provided ads, it’s also likely that they were advertised with Bing as well.

    The entire campaign came to light during WithSecure’s investigation of a ransomware incident at a European IT service provider. It turned out that the fake password manager not only stole credentials but also installed ransomware on the company’s VMware ESXi servers. WithSecure noted that this is the first instance of an open-source password manager being used simultaneously as a credential-stealing tool and malware loader.

    Watch Where You Get Your Programs

    You can use your browser’s password manager with precautions, but using a dedicated program is a much more secure alternative. Hackers target password managers for exactly this reason—it puts risk where you least expect it, meaning they can catch you off guard.

    Related

    Don’t Fall for This Master Password Reset Email

    1Password users are under attack, but it’s relatively simple to keep your account safe.

    You should always download all programs, especially sensitive ones like your password manager, from their official websites or the app store based on your platform. Downloading software and games from third-party websites or torrents always runs the risk of your program coming with a side of malware.

    As an added precaution, I’d also recommend you avoid clicking on ads and sponsored links that encourage you to download a program. Even if the ad shows the legitimate URL for the program, hackers have repeatedly shown that they can bypass ad policies and display legitimate URLs while still redirecting you to fake sites.

    Download Fake manager Password Reminds Watch
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleWe tried on Google’s prototype AI smart glasses
    Next Article MSI’s component showcase at Computex was impressive, but in the end, I fell in love with a bracket
    Techurz
    • Website

    Related Posts

    Opinion

    Former Tesla product manager wants to make luxury goods impossible to fake, starting with a chip

    February 10, 2026
    Opinion

    ‘Chad: the Brainrot IDE’ is a new Y Combinator-backed product so wild, people thought it was fake

    November 13, 2025
    Security

    New AI-Targeted Cloaking Attack Tricks AI Crawlers Into Citing Fake Info as Verified Facts

    October 29, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    College social app Fizz expands into grocery delivery

    September 3, 20251,432 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202514 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202511 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    College social app Fizz expands into grocery delivery

    September 3, 20251,432 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202514 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202511 Views
    Our Picks

    This Sequoia-backed lab thinks the brain is ‘the floor, not the ceiling’ for AI

    February 10, 2026

    Primary Ventures raises healthy $625M Fund V to focus on seed investing

    February 10, 2026

    Vega raises $120M Series B to rethink how enterprises detect cyber threats

    February 10, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.