cognitive cybersecurity intelligence

News and Analysis

Search

Fake KeePass password manager leads to ESXi ransomware attack

Fake KeePass password manager leads to ESXi ransomware attack

For at least eight months, cybercriminals have been distributing trojanized versions of KeePass, a password manager, to install Cobalt Strike beacons, steal credentials, and deploy ransomware on breached networks. The campaign was identified by WithSecure’s Threat Intelligence team, and they discovered that the adversaries had manipulated the open-source code of KeePass to create a version named KeeLoader, which includes a Cobalt Strike beacon and exports the password database. The Cobalt Strike watermarks used in this campaign have been linked to previous Black Basta ransomware attacks.

Source: www.bleepingcomputer.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts