Threat actors from the group CryptoChameleon have launched a sophisticated phishing campaign targeting LastPass users by exploiting the password manager's legitimate legacy inheritance process. Victims receive emails falsely claiming that a family member has submitted a death certificate to gain access to their password vault, with urgent instructions to respond if the recipient is not deceased. The phishing emails contain links to fake LastPass pages designed to steal users' master passwords, and in some cases, attackers have posed as LastPass staff via phone calls to further pressure victims into divulging credentials.
The campaign leverages convincing social engineering tactics, including the use of agent ID numbers and passkey-themed phishing domains such as mypasskey[.]info and passkeysetup[.]com. Attackers also mimic sign-in pages for Gmail, iCloud, Okta, and Outlook to target users' cryptocurrency wallets on platforms like Binance, Coinbase, Kraken, and Gemini. LastPass has warned that these phishing sites are increasingly focused on stealing passkeys, reflecting both the growing adoption of passkeys and their value in protecting high-value assets. Users are advised to remain vigilant and avoid interacting with suspicious emails or providing credentials on unfamiliar sites.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
In the same campaign, LastPass said some phishing sites appeared designed to target passkeys, indicating attackers are adapting social-engineering tactics as passkey adoption grows. The company highlighted risks such as tricking users into registering passkeys on malicious sites or approving fraudulent sync or transfer actions.
LastPass warned users about a phishing campaign in which emails falsely claim the recipient is deceased and that a family member submitted a death certificate to access the victim's password vault. The messages link to a fake LastPass page intended to steal the user's master password by exploiting fear and urgency around legitimate inheritance and emergency-access features.
LastPass said the threat group CryptoChameleon, also tracked as UNC5356, had previously been observed using LastPass branding in a phishing kit. The prior activity was noted as occurring in April 2024 and provides context for the later campaign targeting LastPass users.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.