Threat actors have launched sophisticated phishing campaigns impersonating LastPass to trick users into revealing their master passwords and, in some cases, to install remote access tools. One campaign, attributed to the financially motivated group CryptoChameleon (UNC5356), sends emails claiming a family member has requested access to the victim's LastPass vault via a fabricated death certificate, exploiting the service's emergency access feature. Victims are directed to fraudulent sites mimicking LastPass, where they are prompted to enter their credentials or passkeys. In some instances, attackers have also called victims while posing as LastPass staff to further legitimize the scam.
A separate but related campaign targets users of both LastPass and Bitwarden with fake breach notifications, urging them to download a "secure" desktop version of the password manager. The download actually installs the Syncro remote monitoring and management (RMM) tool, which is then used to deploy ScreenConnect for remote access. This allows attackers to steal data, deploy additional malware, and potentially access password vaults. Both LastPass and Syncro have taken steps to warn users and disrupt the malicious infrastructure, emphasizing that no legitimate communication will ever request a master password and advising users to verify suspicious emails.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting highlighted that the campaign's fake LastPass-themed lures, including alarming claims such as breach or death-related notices, were being used to gain remote access and potentially compromise victims' password vaults. The coverage emphasized the risk of attackers using that access to steal sensitive data and credentials.
Cloudflare intervened against the campaign by placing warning pages on the phishing domains used to lure victims. This disrupted access to the malicious infrastructure supporting the fake password manager downloads.
Syncro took action to disable the malicious installations of its software that were being used in the phishing operation. This was part of the response to the abuse of legitimate remote management tooling in the attack chain.
LastPass issued an advisory stating that the emails were fraudulent and that the company had not suffered a breach. It also reminded users it would never ask for their master password and provided guidance for reporting suspicious messages.
Victims who downloaded the fake password manager binary installed Syncro, a remote monitoring and management tool, which was then used to deploy ScreenConnect. This gave the attackers remote control of affected systems, enabling data theft, additional malware deployment, and possible access to password vaults.
Threat actors launched a phishing campaign sending fake breach notification emails to users of LastPass and Bitwarden. The messages attempted to trick recipients into downloading a fraudulent desktop application for the password managers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.