Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Netflix growing up, data center jet engines, and the circular AI economy

    December 12, 2025

    What most VCs won’t tell you about raising capital

    December 12, 2025

    Retro, a photo-sharing app for friends, lets you ‘time-travel’ through your camera roll

    December 12, 2025
    Facebook X (Twitter) Instagram
    Trending
    • Netflix growing up, data center jet engines, and the circular AI economy
    • What most VCs won’t tell you about raising capital
    • Retro, a photo-sharing app for friends, lets you ‘time-travel’ through your camera roll
    • The market has ‘switched’ and founders have the power now, VCs say
    • Capital is a commodity (but your investor relationships aren’t)
    • Harness hits $5.5B valuation with $240M raise to automate AI’s ‘after-code’ gap
    • On Me raises $6M to shake up the gift card industry
    • Interest in Spoor’s bird monitoring AI software is soaring
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Guides»This Fake Password Manager Reminds You to Watch Where You Download From
    Guides

    This Fake Password Manager Reminds You to Watch Where You Download From

    TechurzBy TechurzMay 21, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    This Fake Password Manager Reminds You to Watch Where You Download From
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Downloading programs is an easy enough task, but only if you’re using official websites or app stores. If you use third-party sources or torrents, this fake password manager is a good reminder of why the official sources are best.

    This Password Manager Steals Your Passwords

    Security researchers at WithSecure have discovered a malware campaign in which hackers have been delivering trojanized versions of the KeePass password manager since at least October 2024. These versions install malware called Cobalt Strike along with the password manager, which can steal saved passwords and other credentials from your PC and deploy ransomware on your network.

    Since KeePass is open source, hackers easily accessed the source code to create a convincing clone. This malicious version is called KeeLoader and contains all of KeePass’ functionality, except it saves all your passwords as a text file and sends them to hackers using Cobalt Strike beacons.

    The distribution is handled by fake websites that use typo-squatted domains like the following:

    • keeppaswrd.com
    • keegass.com
    • KeePass.me
    • keespass.biz
    • keebass.com
    • KeePassx.com

    Some of these domains are still active and distributing fake versions of KeePass. For context, the legitimate KeePass website is at keepass.info. The fake websites were available via Microsoft’s Bing search engine. WithSecure claims that the fake domains were being served through DuckDuckGo advertisements. However, given that Microsoft and DuckDuckGo have formed a partnership on Microsoft-provided ads, it’s also likely that they were advertised with Bing as well.

    The entire campaign came to light during WithSecure’s investigation of a ransomware incident at a European IT service provider. It turned out that the fake password manager not only stole credentials but also installed ransomware on the company’s VMware ESXi servers. WithSecure noted that this is the first instance of an open-source password manager being used simultaneously as a credential-stealing tool and malware loader.

    Watch Where You Get Your Programs

    You can use your browser’s password manager with precautions, but using a dedicated program is a much more secure alternative. Hackers target password managers for exactly this reason—it puts risk where you least expect it, meaning they can catch you off guard.

    Related

    Don’t Fall for This Master Password Reset Email

    1Password users are under attack, but it’s relatively simple to keep your account safe.

    You should always download all programs, especially sensitive ones like your password manager, from their official websites or the app store based on your platform. Downloading software and games from third-party websites or torrents always runs the risk of your program coming with a side of malware.

    As an added precaution, I’d also recommend you avoid clicking on ads and sponsored links that encourage you to download a program. Even if the ad shows the legitimate URL for the program, hackers have repeatedly shown that they can bypass ad policies and display legitimate URLs while still redirecting you to fake sites.

    Download Fake manager Password Reminds Watch
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleWe tried on Google’s prototype AI smart glasses
    Next Article MSI’s component showcase at Computex was impressive, but in the end, I fell in love with a bracket
    Techurz
    • Website

    Related Posts

    Opinion

    ‘Chad: the Brainrot IDE’ is a new Y Combinator-backed product so wild, people thought it was fake

    November 13, 2025
    Security

    New AI-Targeted Cloaking Attack Tricks AI Crawlers Into Citing Fake Info as Verified Facts

    October 29, 2025
    Opinion

    TechCrunch Disrupt 2025: How to watch the Startup Battlefield finale, Cluely, Solana, SF’s Mayor

    October 29, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    College social app Fizz expands into grocery delivery

    September 3, 202520 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202513 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 20259 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    College social app Fizz expands into grocery delivery

    September 3, 202520 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202513 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 20259 Views
    Our Picks

    Netflix growing up, data center jet engines, and the circular AI economy

    December 12, 2025

    What most VCs won’t tell you about raising capital

    December 12, 2025

    Retro, a photo-sharing app for friends, lets you ‘time-travel’ through your camera roll

    December 12, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2025 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.