Threat Advisory

Fake Support Centers Exploit LastPass Users to Steal Data

Threat: Malicious Campaign
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A deceptive campaign has been discovered where scammers exploit browser extension reviews to post fake customer support numbers, tricking users into granting access to their devices. These fraudulent reviews target users of a widely used password management tool, promoting a fake support number, 805-206-2892. When victims call this number, they are directed to a malicious site where they are instructed to download remote support software. This software enables attackers to gain full control over the victim’s computer. While keeping the victim engaged in conversation, the attackers use this access to install additional tools, steal sensitive data, and compromise the security of stored passwords, posing significant risks to users.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A deceptive campaign has been discovered where scammers exploit browser extension reviews to post fake customer support numbers, tricking users into granting access to their devices. These fraudulent reviews target users of a widely used password management tool, promoting a fake support number, 805-206-2892. When victims call this number, they are directed to a malicious site where they are instructed to download remote support software. This software enables attackers to gain full control over the victim’s computer. While keeping the victim engaged in conversation, the attackers use this access to install additional tools, steal sensitive data, and compromise the security of stored passwords, posing significant risks to users.[emaillocker id="1283"]

The campaign relies on manipulated reviews to build trust and lure users into interacting with the fake support system. Victims are guided to a malicious website where they download software that provides remote access to their computers. Once connected, attackers leverage this access to deploy additional tools or create backdoors for persistent control. The attackers use sophisticated social engineering techniques, keeping the victims occupied while carrying out malicious activities in the background. This combination of technical exploitation and psychological manipulation makes the campaign particularly dangerous, as it can bypass the security measures of unsuspecting users and compromise sensitive information.

The fake support number is part of a larger campaign targeting multiple well-known brands across various sectors, including payment systems, streaming platforms, and cloud storage providers. Attackers disseminate these fake numbers through user-generated platforms such as forums and reviews, making them difficult to identify and remove entirely. Although some posts are removed, new ones appear frequently, showcasing the persistence of this operation. Users are encouraged to remain cautious and avoid sharing sensitive credentials with any support representative. This campaign highlights the need for stronger content monitoring and enhanced security measures to prevent such fraudulent activities from impacting broader user communities.

THREAT PROFILE:

Tactic Technique ID Technique
Resource Development T1583 Acquire Infrastructure
Initial Access T1566 Phishing
Execution T1204 User Execution
Persistence T1547 Boot or Logon Autostart Execution
Privilege Escalation T1055 Process Injection
Credential Access T1003 OS Credential Dumping
Discovery T1083 File and Directory Discovery
Lateral Movement T1021 Remote Services
Collection T1114 Email Collection
Command and Control T1105 Ingress Tool Transfer
Impact T1486 Data Encrypted for Impact

REFERENCES:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/lastpass-warns-of-fake-support-centers-trying-to-steal-customer-data/

[/emaillocker]
crossmenu