Security News > 2021 > April > Passwordstate Warns of Ongoing Phishing Attacks Following Data Breach
Click Studios, the Australian software firm which confirmed a supply chain attack affecting its Passwordstate password management application, has warned customers of an ongoing phishing attack by an unknown threat actor.
"We have been advised a bad actor has commenced a phishing attack with a small number of customers having received emails requesting urgent action," the company said in an updated advisory released on Wednesday.
While Passwordstate serves about 29,000 customers, the Adelaide-based firm maintained that the total number of impacted customers is very low.
"The original attack was carried out via a trojanized Passwordstate update file containing a modified DLL that, in turn, extracted retrieved a second-stage payload from a remote server so as to extract sensitive information from compromised systems. As a countermeasure, Click Studios released a hotfix package named"Moserware.
The newly spotted phishing attack involves crafting seemingly legitimate email messages that "Replicate Click Studios email content" - based on the emails that were shared by customers on social media - to push a new variant of the malware.
"The phishing attack is requesting customers to download a modified hotfix Moserware.zip file, from a CDN Network not controlled by Click Studios, that now appears to have been taken down," the company said.
News URL
Related news
- Tech giant Nidec confirms data breach following ransomware attack (source)
- Henry Schein discloses data breach a year after ransomware attack (source)
- Free Sniper Dz Phishing Tools Fuel 140,000+ Cyber Attacks Targeting User Credentials (source)
- DOJ, Microsoft seize 107 domains used in Russia's Star Blizzard phishing attacks (source)
- Dutch Police: ‘State actor’ likely behind recent data breach (source)
- Comcast and Truist Bank customers caught up in FBCS data breach (source)
- Internet Archive hacked, data breach impacts 31 million users (source)
- Internet Archive data breach, defacement, and DDoS: Users’ data compromised (source)
- Fidelity Investments says data breach affects over 77,000 people (source)
- Fidelity Data Breach Exposes Data of Over 77,000 Customers (source)