LastPass attack saw employee’s home computer hacked

designer491 – stock.adobe.com

The ongoing investigation into a series of linked security incidents at LastPass has found that the attacker was successfully able to compromise a developer’s home PC using a vulnerability in a media software package

Alex Scroxton

By

Published: 28 Feb 2023 12:45

The threat actor behind a series of compromises of credential management specialist LastPass attacked a DevOps engineer’s home computer to gain access to the organisation’s decryption keys, it has emerged.

The first attack took place in August 2022, and saw LastPass praised for its swift response to the incident, which saw the attacker access some source code and proprietary technical information.

They then used the information obtained at that point – prior to a reset completed by LastPass – to enumerate and exfiltrate data from cloud storage resources, in a second, deeper and longer-lasting intrusion, disclosed in December 2022, that saw them access customer data.

Compromised customer data included account information such as company and user names, billing addresses, email addresses, telephone numbers and IP addresses from where they accessed LastPass.

The cyber criminals also accessed a backup of customer vault data including encrypted fields, but as these are encrypted with 256-bit AES encryption and can only be decrypted using a key derived from the user’s master password, which is never known by LastPass, this would be very difficult to achieve as long as the user was following recommended best practice.

Initially, LastPass revealed only that the attacker targeted a developer’s endpoint, but the investigation has now turned up more details.

“Due to the security controls protecting and securing the on-premise datacentre installations of LastPass production, the threat actor targeted one of the four DevOps engineers who had access to the decryption keys needed to access the cloud storage service,” LastPass revealed in a new update.

“This was accomplished by targeting the DevOps engineer’s home computer and exploiting a vulnerable third-party media software package, which enabled remote code execution [RCE] capability and allowed the threat actor to implant keylogger malware. The threat actor was able to capture the employee’s master password as it was entered, after the employee authenticated with MFA, and gain access to the DevOps engineer’s LastPass corporate vault.

“The threat actor then exported the native corporate vault entries and content of shared folders, which contained encrypted secure notes with access and decryption keys needed to access the AWS S3 LastPass production backups, other cloud-based storage resources and some related critical database backups,” the organisation said.

It added that the engineer in question has been receiving support in hardening their home network and equipment.

LastPass said that due to the differing tactics, techniques and procedures (TTPs) used in the attack chain, it had not been immediately obvious that what appeared at first to be two different incidents were in fact linked.

Additionally, it added, alerting and logging had been enabled throughout the events but did not immediately indicate the anomalous behaviour that later became more obvious. The fact that the unlucky engineer’s valid credentials were being used to access a shared cloud storage environment made it harder to differentiate between legitimate and illegitimate activity.

Ultimately, LastPass said, it had AWS to thank – it was the supplier’s GuardDuty Alerts that flagged anomalous behaviour as the attacker tried to use cloud identity and access management roles to perform unauthorised activity.

Since the attack, LastPass has taken a number of steps to harden its own cyber security, including rotating critical and high-privilege credentials, revoking and reissuing the compromised certificates, and applying additional hardening measures to its AWS S3 resources.

Given the apparent failings in its ability to respond swiftly to alerts, it has also revised its threat detection and response coverage, and on-boarded new automated and managed services to assist with this, including custom analytics to detect potential abuse of AWS resources.

Read more on Data breach incident management and recovery

Read More
Qiana Buresh

Latest

Smoke-Free Drive! Lahore to Suspend Licences of Drivers of Smoke-Emitting Vehicles

Lahore traffic authorities have taken a tough step against air pollution. Chief Traffic Officer (CTO) Syed Abdul Raheem Shirazi announced that drivers of smoke-emitting vehicles will now have their driving licences suspended. Commercial vehicles that break emission rules may also lose their route permits. The decision is part of a zero-tolerance campaign to reduce smog

Australian small business sales cool off in the June quarter

Xero economist Louise Southall says small businesses are “thinking carefully” before hiring as rate rises and fuel costs bite. Key insights: New Xero Small Business Insights data shows Australian small business sales growth eased to 6.5 per cent year-on-year in the June quarter, down from a two-year high of 7.9 per cent in Q1. Hospitality, retail

Sri Lanka prepares for impending El Niño with traditional and new approaches

According to traditional Sri Lankan paddy farmers, long dry spells have occurred every four to seven years. Sri Lanka has experienced around 25-26 El Niño events from 1950 to date, out of which only three have been strong El Niño events, meteorology department officials say. The irrigation department has introduced new water-saving techniques such as

Liverpool in contact with former Chelsea defender

Liverpool continue their pre-season campaign with a friendly against Premier League rivals Leeds United on Sunday.  Rio Ngumoha’s goal earned the Reds a narrow 1-0 victory over Wrexham in their last outing, and new manager Andoni Iraola will hope to see his side build on that result when they face the Whites in Chicago, Illinois.

Newsletter

Don't miss

Smoke-Free Drive! Lahore to Suspend Licences of Drivers of Smoke-Emitting Vehicles

Lahore traffic authorities have taken a tough step against air pollution. Chief Traffic Officer (CTO) Syed Abdul Raheem Shirazi announced that drivers of smoke-emitting vehicles will now have their driving licences suspended. Commercial vehicles that break emission rules may also lose their route permits. The decision is part of a zero-tolerance campaign to reduce smog

Australian small business sales cool off in the June quarter

Xero economist Louise Southall says small businesses are “thinking carefully” before hiring as rate rises and fuel costs bite. Key insights: New Xero Small Business Insights data shows Australian small business sales growth eased to 6.5 per cent year-on-year in the June quarter, down from a two-year high of 7.9 per cent in Q1. Hospitality, retail

Sri Lanka prepares for impending El Niño with traditional and new approaches

According to traditional Sri Lankan paddy farmers, long dry spells have occurred every four to seven years. Sri Lanka has experienced around 25-26 El Niño events from 1950 to date, out of which only three have been strong El Niño events, meteorology department officials say. The irrigation department has introduced new water-saving techniques such as

Liverpool in contact with former Chelsea defender

Liverpool continue their pre-season campaign with a friendly against Premier League rivals Leeds United on Sunday.  Rio Ngumoha’s goal earned the Reds a narrow 1-0 victory over Wrexham in their last outing, and new manager Andoni Iraola will hope to see his side build on that result when they face the Whites in Chicago, Illinois.

This $29 rack fixed my out-of-control keyboard and mouse collection

When you purchase through links in our articles, we may earn a small commission. This doesn't affect our editorial independence . Australian Editor, PCWorld A simple acrylic rack keeps my 5+ gaming keyboards and mice organized, stacked, and within reach. Goodbye desk clutter, hello sanity. One thing I’ve learned over the years is that there’s

Global Business Travel Spending to Hit Record $1.71 Trillion in 2026, While Trips Reach 1.84 Billion, Says GBTA Forecast

In Brief: GBTA’s latest Business Travel Index report shows spending gains driven by higher prices as geopolitical uncertainty and transportation pressures weigh on the outlook Global Business Travel Spending to Hit Record $1.71 Trillion in 2026, While Trips Reach 1.84 Billion, Says GBTA Forecast - Image Credit Unsplash+    Global business travel spending is forecast to

Boulevard Business Park: Saudi Arabia’s Bold Bet on Mixed-Use Development

Boulevard Business Park Saudi Arabia has marked another milestone in its urban and entertainment transformation with the completion of the Kingdom’s first entertainment-focused business park and corporate resort. This remarkable achievement reflects a new approach to commercial development that thoughtfully blends business, hospitality and leisure within a single destination. More Than an Office Park Located

How Chaoshan Business Was Built on Morals, Not Contracts

This is the second article in a series on China's southern Chaoshan region, exploring the history, culture, and identities behind its recent resurgence in the spotlight. Read Part 1. In the Chinatowns of early 20th-century Bangkok, Chinese laborers who had just collected their wages would make their way to the qiaopiju, a private institution that