Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Your fitbit sleep score just worse – why is this good news here

    August 5, 2025

    My Go -TU LLM Tool dropped a super simple Mac and PC app for the local AI – why should you try it

    August 5, 2025

    The base network is suffering from 1 downtime since 2023, prevents operations for 29 minutes

    August 5, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Fake Keepus Password Manager leads to ESXI ransomware attack
    Security

    Fake Keepus Password Manager leads to ESXI ransomware attack

    PineapplesUpdateBy PineapplesUpdateMay 20, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Fake Keepus Password Manager leads to ESXI ransomware attack
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Fake Keepus Password Manager leads to ESXI ransomware attack

    Threatening actor Cobalt Strike Beckon, Stolen Credit Crearent, and eventually, are distributing the traogenous versions of Tranged Password Manager for at least eight months to deploy ransomware on violated networks.

    After bringing to check the ransomware attack, the Threat Intelligence Team of WITHSECURE discovered the campaign. Researchers found that the attack began with a malicious ingestion installer through Bing advertisements, which promoted fake software sites.

    As the Keepass is an open source, the danger actors replaced the source code to create a trojan version, dubbed Keeloader, including all general password management functionality. However, this includes modifications that install cobalt strike beacons and export the Keepass password database as Cleastext, which is then stolen through beacons.

    WithSecure says the cobalt strike watermarks used in this campaign are associated with an early access broker (IAB), which is believed to have been associated with black bag ransomware attacks in the past.

    Cobalt strike watermark is a unique identifier embedded in a beacon that is bound by license used to generate payloads.

    “This watermark is usually noted in terms of beacons and domains related to black bag ransomware. It is used by danger actors, who are working as an early access broker working together with Black Basta,” Furore,

    “We do not know about any other events (ransomware or otherwise) using this cobalt strike beacon watermark – this does not mean that it has not happened.”

    Researchers have found that several variants of the sectioner have been discovered, signed with valid certificates, and typo-scvating domains such as kipasplud (.) Com, Kigas (.) Com, and spread through Keepus (.) Com, and Keepus (.).

    Bleepingcomputer has confirmed that Keeppaswrd (.) Com The website is still active and continues to distribute the Troined Keepass Installer (Wirstotal,

    Fake Keepass site is pushing the Trochaised Installer
    Fake Keepass site is pushing the Trochaised Installer
    Source: Bleepingcomputer

    In addition to leaving the cobalt strike beacon, the Troying Caps program included a password-fanfast functionality, which allowed the danger actors to steal any credentials input in the program.

    “Caloder was not only modified to the extent that it can act as a malware loader. Its functionality was extended to facilitate the exfiltration of the keepass database data,” reads in the withsecure report.

    “When the keepass database data was opened; account, login name, password, website, and comments also exports as .KP under % Localappdata % in CSV format.

    Dumping insect credentials
    Dumping insect credentials
    Source: Classure

    Eventually, the attack by Vithsecure encrypted the company’s VMWARE ESXI server with ransomware.

    Further investigation of the campaign found a broader infrastructure that was designed to distribute malicious malicious programs in the form of legitimate equipment and fishing pages, designed to steal credentials.

    Aenys (.) Com Domain was used to host additional subdomains, which were to implement famous companies and services like WinScp, Pumpfun, Phantom Wallet, Rallie Mae, Woodforest Bank and Dex Screner.

    Each of these was used to distribute various malware variants or stolen credentials.

    WithSecure This activity is associated with the first nitrogen loader campaigns with a dangerous actor group, with moderate confidence for UnC4696. The previous nitrogen campaigns were connected to Blackcat/Alphv ransomware.

    Users are always advised to download software, especially highly sensitive such as password managers, from legitimate sites, and to avoid any site involving advertisements.

    Even if an advertisement displays the correct URL for a software service, it should still be avoided, as danger actors have repeatedly proved that they can ignore Ad policies to display legitimate URLs while joining Eposter sites.


    Red Report 2025

    Based on the analysis of 14M malicious tasks, search for the top 10 MITERAT & CK techniques behind the 93% attacks and how to defend them against them.

    Attack ESXI fake Keepus leads manager password Ransomware
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHere is the OURA ring data that you can access without subscription
    Next Article JP Morgan to cut headcount in some divisions due to AI
    PineapplesUpdate
    • Website

    Related Posts

    Security

    This Palm -Acar’s power bank can charge many devices at once – and I am for all the price.

    August 5, 2025
    Security

    Android gets patches for exploited Qualcomm defects in attacks

    August 5, 2025
    Security

    5 hard truth of a career in cyber security – and how to navigate them

    August 5, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    Your fitbit sleep score just worse – why is this good news here

    August 5, 2025

    My Go -TU LLM Tool dropped a super simple Mac and PC app for the local AI – why should you try it

    August 5, 2025

    The base network is suffering from 1 downtime since 2023, prevents operations for 29 minutes

    August 5, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.