Hackers are fraudulently exploiting Google ads to target users of Bitwarden and other password managers, trying to steal their password vault credentials.

In today's digital world, having a different password for every website is no longer an option - it's a necessity. As such, using reliable password managers has become more vital than ever to ensure you can safely remember all your passwords.
See also: FBI hacked into Hive ransomware group's systems
However, unless you opt for a local password manager like KeePass, most password managers are cloud – giving users the ability to easily access their passwords via websites and mobile apps.
To ensure maximum security, user passwords are securely stored and encrypted in the cloud using “password vaults” and users’ individual master passwords.
Recent security breaches at LastPass and credential stuffing attacks at Norton have shown that a master password is a weak point for a password vault.
As a result, cybercriminals have been observed creating malicious phishing pages targeting password vault login credentials and even authentication cookies. If they gain access to these details, then their infiltration of your vault is complete.
See also: Realtek SDK vulnerability used in 134 million attacks
Bitwarden users targeted by Google ads phishing
On Tuesday, Bitwarden users discovered a Google ad titled “Bitward – Password Manager” when they searched for “bitwarden password manager” in the search engine results.
Although BleepingComputer was unable to reproduce the ad, several Bitwarden users posted about it on Reddit[1,2] and the Bitwarden forums.
The domain used in the ad was “appbitwarden.com” and, when clicked, users were redirected to the website “bitwardenlogin.com”.

The fraudulent page at “bitwardenlogin.com” was an exact copy of the authentic Bitwarden Web Vault login page, as shown below.

Bleepingcomputer conducted tests to prove that the phishing page readily accepts credentials and, after submitting the data, will seamlessly redirect users to the official Bitwarden login page.
Initially, Bleepingcomputer's tests involved using fake credentials. Unfortunately, when they switched to real logins to test Bitwarden for further testing, the page was already down.
What's even worse is that Bitwarden isn't the only one being targeted by these malicious phishing pages in Google ads.
Recently, MalwareHunterTeam, a security researcher, detected malicious Google ads that were trying to access the credentials of the password manager 1Password.
See also: Lexmark: Fixed vulnerability affecting many printers
Recent studies have shown that cybercriminals are increasingly using Google ads to facilitate malware delivery campaigns, steal credentials , and carry out phishing attacks in attempts to gain access to corporate networks.
Information source: bleepingcomputer.com
