Mashable 02月13日
Hackers are targeting your password manager app
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

密码管理器因其便捷性受到广泛使用,但同时也成为网络犯罪分子的重点攻击对象。网络安全公司Picus Security的报告显示,针对密码管理器和浏览器存储凭据等服务的网络攻击比去年增加了两倍。研究发现,在超过一百万种恶意软件变种中,有25%针对密码管理器或其他凭据存储服务。网络罪犯越来越多地采用多阶段攻击,窃取密码存储中的凭据已成为MITRE ATT&CK框架中的十大技术之一。专家建议,密码管理器应与多因素身份验证结合使用,且员工不应重复使用密码,尤其是用于密码管理器的密码。

🔐密码管理器因其便捷性,被越来越多的人使用,方便用户登录各种应用、社交媒体账户和其他在线服务。

🚨网络安全公司Picus Security的报告指出,针对密码管理器和类似服务的网络攻击比去年增加了两倍,情况不容乐观。

⚔️网络罪犯正在部署多阶段攻击,被称为“SneakThief”,这种新型恶意软件攻击包含数十种恶意行为,旨在秘密获取和导出数据。

🛡️Picus Security建议将密码管理器与多因素身份验证结合使用,并强调员工不应重复使用密码,尤其是用于密码管理器的密码,以增强安全性。

Do you use 1Password, LastPass, NordPass, or any other password manager? You're not alone. According to a 2023 Security.org study, roughly one in three people use a password manager to secure their login information. Password managers make logging in to your apps, social media accounts, and other online services easy.

They're also increasingly being targeted by cybercriminals.

According to a new report from cybersecurity firm Picus Security, cyberattacks on password managers and similar services, such as browser-stored credentials, have tripled compared to the previous year. The firm detailed these findings in its Red Report 2025.

Researchers found that out of more than a million malware variants, 25 percent of all malware targeted password managers or other credential storage services.

"For the first time ever, stealing credentials from password stores is in the top 10 techniques listed in the MITRE ATT&CK Framework," Picus Security said, referencing an industry framework for classifying cyberattacks.

According to Picus, cybercriminals are increasingly deploying multi-stage attacks, which the firm's researchers have dubbed "SneakThief." SneakThief describes a new type of malware attack that involves "increased stealth, persistence, and automation." These new malware attacks contain dozens of "malicious actions," which aid the hacker in gaining access and exporting data without getting caught.

With so many apps and online platforms to manage logins for, more internet users have adopted password storage utilities to help manage them all. But, in turn, hackers have adjusted their malicious campaigns to shift their focus towards password managers. And it makes sense. Why would a hacker put their time and effort into stealing a target's login credentials to just one service when they could steal all their login credentials? Why steal a key to open just one door when you can take the master key and access everything?

"Threat actors are leveraging sophisticated extraction methods, including memory scraping, registry harvesting, and compromising local and cloud-based password stores, to obtain credentials that give attackers the keys to the kingdom," said Picus Security co-founder and VP of Picus Labs, Dr. Suleyman Ozarslan. "It’s vital that password managers are used in tandem with multi-factor authentication and that employees never reuse a password, especially for their password manager."

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

密码管理器 网络安全 Picus Security 网络攻击
相关文章