Phishing Alert: Fake ‘LastPass Hack’ Emails Spreading Malware
On Mon, Oct 13, 2025, a new phishing campaign targeting LastPass users was identified. The campaign disseminates deceptive emails falsely claiming to be from “hello@lastpasspulse.blog” or “hello@lastpassgazette.blog” with the subject line “We Have Been…
On Mon, Oct 13, 2025, a new phishing campaign targeting LastPass users was identified. The campaign disseminates deceptive emails falsely claiming to be from “hello@lastpasspulse.blog” or “hello@lastpassgazette.blog” with the subject line “We Have Been Hacked – Update Your LastPass Desktop App to Maintain Vault Security.”
Contrary to these claims, LastPass has not been compromised. The emails use fear tactics and urgency to mislead recipients into downloading malicious software.
The emails resemble authentic LastPass communications and urge users to update their desktop app to protect their vaults. However, the embedded links redirect to malicious domains rather than legitimate LastPass pages. These domains include “lastpassdesktop.com” (IP 172.67.147.36) and “lastpassgazette.blog” (IP 84.32.84.32). Another domain, “lastpassdesktop.app” (IP 172.67.219.2), has been pre-registered, suggesting further phishing activities.
Hosted by NICENIC, a known provider resistant to takedown requests, these domains aim to exploit the U.S. holiday weekend’s reduced security monitoring.
Threat Actor Tactics and Technical Indicators
The campaign primarily relies on social engineering, exploiting panic and urgency to deceive users into executing malware. Indicators of compromise include:
On Mon, Oct 13, 2025, a new phishing campaign targeting LastPass users was identified.
Sender Addresses: Authentic LastPass servers do not use “@lastpasspulse.blog” or “@lastpassgazette.blog.” Domain Registrations: Recent registrations with minimal WHOIS data, unaffiliated with LastPass. Hosting Provider: Use of NICENIC, known for illicit operations. Timing: Launched during a holiday to exploit monitoring delays.
The phishing sites lack proper TLS certificates, and although warnings from Cloudflare exist, they may be ignored by users under pressure.
LastPass users should remain cautious, noting that LastPass will not request master passwords or unverified updates. If suspicious emails are received:
Avoid clicking links or downloading attachments. Verify the sender’s domain for errors. Hover over links to verify the destination domain. Report such emails to abuse@lastpass.com.
LastPass is working with domain registrars, hosting providers, and law enforcement on takedowns. Cloudflare has already placed warnings on the malicious sites. Users are advised to enable multi-factor authentication on LastPass accounts and maintain updated antivirus software to enhance security.
By staying informed and scrutinizing unexpected security alerts, users can secure their credentials and protect their password vaults effectively.
Based on reporting by GBHackers.
