Home Password managers are hackers’ new target according to report

Password managers are hackers’ new target according to report

TLDR

  • Picus Security reports that 25% of malware now targets password managers like 1Password.
  • Hackers use methods like memory scraping and registry harvesting to steal stored credentials.
  • Enabling two-factor authentication (2FA) is recommended to enhance password security.

Password managers like 1Password are the new targets for hackers, according to a new report. Picus Security has revealed that according to its latest research, 25% of malware now targets these password stores.

A majority of password managers will have some form of additional security before you’re able to access them. For instance, on iPhones, the web browser Firefox will ask for Face ID before unlocking its built-in password manager. However, on PC, this is unprotected if you’re logged in, making it a potential target.

Some other apps will also leave this unprotected once logged in, but the discovered malware is also digging deep into operating systems like Windows. According to the Vice President of Picus Labs, Dr. Suleyman Ozarslan, malicious actors are programming malware to perform all manner of attacks.

In the press release, Dr. Ozarslan said, “Threat actors are leveraging sophisticated extraction methods, including memory scraping, registry harvesting and compromising local and cloud-based password stores, to obtain credentials that give attackers the keys to the kingdom.”

Applications like 1Password will have a “master password”, which once acquired, can cause major damage. However, the news might not slow down the adoption of the software.

As mentioned above, browsers now come with their own built-in password managers. Applications like LastPass and NordPass are ever popular due to the ever-rising need for complex passwords that even the user won’t remember.

How to fight back against password manager hackers

It’s recommended that you apply two-factor authentication (2FA) to any highly important accounts. This can tie in with an authenticator from Google, which generates a rotating string of numbers that need to be input before access can be granted. At the most basic level, text messaging 2FA should be turned on.

While passwords are constantly at risk, companies like Microsoft and Apple are slowly trying to migrate their users away from them. Passkeys or biometric IDs are becoming more prevalent, and in 2024, Microsoft removed passwords for 1 billion users. The Seattle giant also has a list of banned passwords on its Azure cloud service.

Picus Labs evaluated and processed 1, 094, 744 pieces of malware throughout 2024. Through these, it found over 14 million “malicious actions” embedded in them. Interestingly, they found that there was “no significant increase” in “AI-driven malware” in 2024, despite the concerns surrounding the technology and cybersecurity.

About ReadWrite’s Editorial Process

The ReadWrite Editorial policy involves closely monitoring the gambling and blockchain industries for major developments, new product and brand launches, game releases and other newsworthy events. Editors assign relevant stories to in-house staff writers with expertise in each particular topic area. Before publication, articles go through a rigorous round of editing for accuracy, clarity, and to ensure adherence to ReadWrite's style guidelines.

Joel Loynds
Tech Journalist

Joel Loynd’s obsession with uncovering bad games and even worse hardware so you don’t have to has led him on this path. Since the age of six, he’s been poking at awful games and oddities from his ever-expanding Steam library. He’s been writing about video games since 2008, writing for sites such as WePC and PC Guide, as well as covering gaming for Scan Computers, More recently Joel was Dexerto’s E-Commerce and Deputy Tech Editor, delving deep into the exploding handheld market and covering the weird and wonderful world of the latest tech.

Get the biggest iGaming headlines of the day delivered to your inbox

    By signing up, you agree to our Terms and Privacy Policy. Unsubscribe anytime.

    Gambling News

    Explore the latest in online gambling with our curated updates. We cut through the noise to deliver concise, relevant insights, keeping you informed about the ever-changing world of iGaming and its most important trends.

    In-Depth Strategy Guides

    Elevate your game with tailored strategies for sports betting, table games, slots, and poker. Learn how to maximize bonuses, refine your tactics, and boost your chances to beat the house.

    Unbiased Expert Reviews

    Honest and transparent reviews of sportsbooks, casinos and poker rooms crafted through industry expertise and in-depth analysis. Delve into intricacies, get the best bonus deals, and stay ahead with our trustworthy guides.