Do you use 1Password,Big Thing Chief: The Stolen Wife LastPass, NordPass, or any other password manager? You're not alone. According to a 2023 Security.org study, roughly one in three people use a password manager to secure their login information. Password managers make logging in to your apps, social media accounts, and other online services easy.
They're also increasingly being targeted by cybercriminals.
According to a new report from cybersecurity firm Picus Security, cyberattacks on password managers and similar services, such as browser-stored credentials, have tripled compared to the previous year. The firm detailed these findings in its Red Report 2025.
Researchers found that out of more than a million malware variants, 25 percent of all malware targeted password managers or other credential storage services.
"For the first time ever, stealing credentials from password stores is in the top 10 techniques listed in the MITRE ATT&CK Framework," Picus Security said, referencing an industry framework for classifying cyberattacks.
According to Picus, cybercriminals are increasingly deploying multi-stage attacks, which the firm's researchers have dubbed "SneakThief." SneakThief describes a new type of malware attack that involves "increased stealth, persistence, and automation." These new malware attacks contain dozens of "malicious actions," which aid the hacker in gaining access and exporting data without getting caught.
SEE ALSO: How to spot and avoid the E-ZPass scam texts everyone's gettingWith so many apps and online platforms to manage logins for, more internet users have adopted password storage utilities to help manage them all. But, in turn, hackers have adjusted their malicious campaigns to shift their focus towards password managers. And it makes sense. Why would a hacker put their time and effort into stealing a target's login credentials to just one service when they could steal all their login credentials? Why steal a key to open just one door when you can take the master key and access everything?
"Threat actors are leveraging sophisticated extraction methods, including memory scraping, registry harvesting, and compromising local and cloud-based password stores, to obtain credentials that give attackers the keys to the kingdom," said Picus Security co-founder and VP of Picus Labs, Dr. Suleyman Ozarslan. "It’s vital that password managers are used in tandem with multi-factor authentication and that employees never reuse a password, especially for their password manager."
Topics Cybersecurity
Ways to meet people while traveling, from apps to social media tipsHerald the Crack of Bats by Adam SobseyFascinating graphics show how far we've come with COVIDHow to fight carCorps de Ballet: An Interview with Irina Kolpakova by Yona Zeldis McDonoughOpenAI is being sued for training ChatGPT with 'stolen' personal dataDoorDash will now process SNAP and EBT online paymentsBooks on the Floor, and Other News by Sadie SteinYou Two Just Crack Each Other Up by Andrew HudginsTwitter's API keeps breaking, even for developers paying $42,000Waugh on Capote by Sadie SteinAssume the more infectious coronavirus variant is in your communityMillennials prioritize sex more than Gen Z does, eharmony says'Quordle' today: See each 'Quordle' answer and hints for June 28Enttäuschung by Sadie SteinEnttäuschung by Sadie SteinIRL, a social app valued at $1 billion, shuts down after revelation that most of its users are fakeHow to watch VR porn: Everything you need to knowTowers of Books! by Sadie SteinA Library Grows in Istanbul, and Other News by Sadie Stein The conversation will be weaponized: Why Facebook, Slack and Cambridge Analytica are the future Google Assistant now lets you send money to friends via Google Pay AeroMobil's latest electric flying car concept hopes to take off in 10 years Who is responsible when a self Zuckerberg's response to Facebook backlash matters more than you think Major snowstorm slams East Coast, to break records from D.C. to Boston Why is cereal is such a miserable sham of a breakfast? Everything you need to know about the March For Our Lives What is ProtonMail, the service used by Cambridge Analytica to cover its tracks? Another Aubrey O'Day song hints at alleged affair with Donald Trump Jr Mark Zuckerberg to finally speak out on Cambridge Analytica scandal People are blaming Toby from 'The Office' for this dreadful winter storm Google Doodle pays tribute to Japanese geochemist Katsuko Saruhashi David Mitchell teases details about his next novel Actual things you can do to bridge the orgasm gap in your own bedroom Snap Map Explore adds text statuses automatically for Snapchat users Creepy AI scans a driver's face and voice to monitor mood and distraction level Google Chrome 66 beta includes autoplay Competing teams are creating devices that extract water from thin air Indeed taps Comparably, InHerSight, Fairygodboss for diversity tool
1.8439s , 8222.8671875 kb
Copyright © 2025 Powered by 【Big Thing Chief: The Stolen Wife】,Exquisite Information Network