Do you use 1Password,Adultery Alumni Association (2018) LastPass, NordPass, or any other password manager? You're not alone. According to a 2023 Security.org study, roughly one in three people use a password manager to secure their login information. Password managers make logging in to your apps, social media accounts, and other online services easy.
They're also increasingly being targeted by cybercriminals.
According to a new report from cybersecurity firm Picus Security, cyberattacks on password managers and similar services, such as browser-stored credentials, have tripled compared to the previous year. The firm detailed these findings in its Red Report 2025.
Researchers found that out of more than a million malware variants, 25 percent of all malware targeted password managers or other credential storage services.
"For the first time ever, stealing credentials from password stores is in the top 10 techniques listed in the MITRE ATT&CK Framework," Picus Security said, referencing an industry framework for classifying cyberattacks.
According to Picus, cybercriminals are increasingly deploying multi-stage attacks, which the firm's researchers have dubbed "SneakThief." SneakThief describes a new type of malware attack that involves "increased stealth, persistence, and automation." These new malware attacks contain dozens of "malicious actions," which aid the hacker in gaining access and exporting data without getting caught.
SEE ALSO: How to spot and avoid the E-ZPass scam texts everyone's gettingWith so many apps and online platforms to manage logins for, more internet users have adopted password storage utilities to help manage them all. But, in turn, hackers have adjusted their malicious campaigns to shift their focus towards password managers. And it makes sense. Why would a hacker put their time and effort into stealing a target's login credentials to just one service when they could steal all their login credentials? Why steal a key to open just one door when you can take the master key and access everything?
"Threat actors are leveraging sophisticated extraction methods, including memory scraping, registry harvesting, and compromising local and cloud-based password stores, to obtain credentials that give attackers the keys to the kingdom," said Picus Security co-founder and VP of Picus Labs, Dr. Suleyman Ozarslan. "It’s vital that password managers are used in tandem with multi-factor authentication and that employees never reuse a password, especially for their password manager."
Topics Cybersecurity
10 trends Gen Z brought back in 2021Macaroon vs. Macaron: Cookie Summit 2015Creators take TikTok Live to the next (terrifying) levelThe iPhone 15 reviews are out. Here are the 3 things people dislike most about it.8 unconventional Christmas music playlists and albumsiPhone 15 FineWoven cases on sale: Save 5% at AmazonThe Forest of Letters: An Interview with Valerie Miles'Twilight' fans love the Edward'Ahsoka' introduces Grand Admiral Thrawn. Is he too late?On the Pleasures of Escaping YourselfStaff Picks: Bernard Berenson, Olivia Laing, Timothy DeneviEavesdropping in the CityInane Puppies: Charlotte Brontë on Men and MarriageBetter Call Caravaggio: “Saul” Borrows from Baroque PaintingWhen Eudora Welty Went Sailing with FaulknerLG Gram 17On the Pleasures of Escaping YourselfBaudelaire Gets Baked: Read His Notes on Smoking HashishBest headphones deal: Get Bose 700 headphones for $80 offThe catchiest earworms of 2021 that you just can't get out of your head Headstone Epitaph Canceling Equity The Devil’s Milkshake Queer History Now! Rush Limbaugh’s Kid Control Radical Dilettantism Imaginary Current Events Morbid Symptoms Women’s Equality—When? The Amazon Has Lost All Subjectivity Holding the Line PEP in Your Step Worst Laid Plans Life and Dream Mucked Up Two Lovers Linsanity and the Art of Escape The President is Arrested East of Dreaming Against the Imposters
2.8074s , 10139.078125 kb
Copyright © 2025 Powered by 【Adultery Alumni Association (2018)】,Creation Information Network