那封关于LastPass或Bitwarden的安全邮件可能是骗局

内容来源:https://lifehacker.com/money/lastpass-bitwarden-security-email-scam?utm_medium=RSS
内容总结:
近期,针对LastPass和Bitwarden密码管理软件用户的网络钓鱼攻击事件频发,诈骗者利用伪造的安全警报诱导用户泄露个人信息。据报道,不法分子冒充官方发送主题为“需采取行动:查阅更新后的LastPass安全政策”的钓鱼邮件,发件地址为hello@lastpassnewsletter.com,要求用户通过DocuSign链接(指向虚假域名lastpasscompliance.com)签署更新条款。Bitwarden用户也遭遇类似攻击,虚假域名bitwardencompliance.com被用于窃取数据。
安全专家指出,此类邮件表面可信度较高,包含技术术语和“账号可能被临时限制”的警告,但发件地址与链接域名均非官方渠道。用户应警惕任何要求输入主密码或下载软件的操作,务必直接登录密码管理器官网或保险库处理账户事宜,切勿通过邮件、短信中的链接操作。若已误填敏感信息,应立即从可信设备修改密码。目前恶意网站已被查封,但具体攻击目标(恶意软件传播或凭据窃取)尚未明确。
中文翻译:
你信任你的密码管理器来保护你的凭证、文档和身份数据——你可能也信任来自密码管理器的通知,其中包含维护这些安全的步骤。诈骗者正是利用了这一点:一场新的网络钓鱼活动正以LastPass和Bitwarden用户为目标,通过伪造的安全警报来窃取数据和入侵设备。
本周早些时候,LastPass向用户发出警告,指出一种冒充诈骗:威胁行为者发送看似官方安全通知的钓鱼邮件。这些邮件来自hello[at]lastpassnewsletter[.]com,主题为“需要操作:审查并接受更新的LastPass安全策略”。
在邮件正文中,攻击者列出了所谓对LastPass安全监控和报告协议的更改,并称用户“有14个工作日通过DocuSign审查并接受更新条款”。链接会跳转到https[:]//lastpasscompliance[.]com/,该页面看起来像是一个合法的DocuSign页面,配有聊天机器人窗口,并提示用户“下载”DocuSign以审查和签署文档。目前尚不清楚目标是传播恶意软件还是窃取用户凭证,因为该恶意网站已被关闭。然而,据BleepingComputer报道,Bitwarden用户也遭遇了几乎完全相同的钓鱼活动。
如何识别密码管理器诈骗
从表面上看,这些针对LastPass和Bitwarden用户的钓鱼邮件相当具有欺骗性。它们包含一些技术术语,因此用户可能会略过细节而相信信息是真实的。邮件中有一个行动号召,但声明用户有14天时间接受条款,否则账户“可能会被临时限制”——这比其他一些诈骗的紧迫感稍低。邮件甚至向用户保证,他们的密码库和账户“完全安全”,并称所需步骤“严格”属于管理性质。
即便如此,发件人和URL本身就应引起怀疑。无论是lastpassnewsletter[.]com还是lastpasscompliance[.]com,都不是LastPass的官方域名;bitwardencompliance[.].com也不是真正的Bitwarden网站。除非你直接导航到密码管理器的网站或密码库,否则切勿输入你的主密码或其他凭证——来自电子邮件、短信或社交媒体消息的链接都有可能是钓鱼尝试。如果你已在可疑网站上提供了凭证,请立即从可信设备上更新这些信息。你也不需要为密码管理器下载软件或使用DocuSign,任何对账户的操作都应在你登录到合法网站或密码库时进行。
英文来源:
You trust your password manager to keep your credentials, documents, and identity data secure—and you probably also trust notices that come from your password manager with steps to maintain that security. Scammers are counting on this: A new phishing campaign is targeting LastPass and Bitwarden users with fake security alerts designed to compromise their data and devices.
Earlier this week, LastPass alerted users to an impersonation scam in which threat actors are sending phishing emails that look like official security notices. The messages come from hello[at]lastpassnewsletter[.]com with the subject line "Action Required: Review Updated LastPass Security Policies."
In the email body, attackers outlined supposed changes to LastPass security monitoring and reporting protocols and noted that users "have 14 business days to review and accept the updated terms" via DocuSign. The link redirected to https[:]//lastpasscompliance[.]com/, which looked like a legitimate DocuSign page complete with a chatbot window, and prompted users to "download" DocuSign in order to review and sign the document. It's unclear whether the goal was to spread malware or harvest user credentials, as the malicious website has since been taken down. However, Bitwarden users have been targeted with a nearly identical campaign, according to BleepingComputer.
How to spot the password manager scam
On the surface, the phishing emails targeting LastPass and Bitwarden users are pretty convincing. They have some technical jargon, so users may skim over the specifics and trust that the information is legitimate. There's a call to action, but the email states that users have 14 days to accept the terms or their account "may be temporarily restricted"—so the urgency is slightly lower than with some other scams. The email even reassures users that their vaults and accounts are "completely secure" and states that the required steps are "strictly" administrative in nature.
That said, both the sender and the URL should raise suspicion. Neither lastpassnewsletter[.]com nor lastpasscompliance[.]com are official LastPass domains, nor is bitwardencompliance[.]com a real Bitwarden site. Never enter your master password or other credentials unless you navigate directly to your password manager's website or vault—links from emails, texts, or social media messages are at risk of being phishing attempts. If you've supplied your credentials to a suspicious site, update them immediately from a trusted device. You also shouldn't need to download software or use DocuSign for your password manager, and any actions on your account should occur when you are logged in to the legitimate site or vault.
文章标题:那封关于LastPass或Bitwarden的安全邮件可能是骗局
文章链接:https://news.qimuai.cn/?post=4590
本站文章均为原创,未经授权请勿用于任何商业用途