WithSecure researchers have uncovered a long-running malicious campaign using compromised versions of the popular password manager KeePass to install Cobalt Strike beacons, steal credentials, and deploy ransomware .
The discovery was made as part of a ransomware investigation, where trojanized installers for KeePass were found, distributed through deceptive ads on Bing, leading users to fake software websites.
Taking advantage of KeePass' open-source nature , the attackers modified the source code to create a variant called KeeLoader . The modified software retains full functionality of the original KeePass , but contains malicious code that installs a Cobalt Strike beacon and extracts the KeePass password database in plain text.
See also: Ransomware gangs use Skitnet malware

According to WithSecure, the Cobalt Strike watermarks observed are associated with an initial access broker (IAB) that has previously been linked to Black Basta ransomware.
WithSecure researchers have uncovered the existence of multiple variants of the malicious KeeLoader, which are signed with valid digital certificates and distributed via deceptive typo-squatting domains, such as keeppaswrd[.]com, keegass[.]com, and KeePass[.]me.
The BleepingComputer team has confirmed that at least one of these websites – specifically keeppaswrd[.]com – remains active and continues to distribute the infected installation file, according to a related entry on VirusTotal.
In addition to installing Cobalt Strike beacons for remote control, the compromised versions of KeePass also feature mechanism password-stealing, giving attackers access to all credentials entered into the application.
"KeeLoader was not limited to the role of a simple malware loader," WithSecure says in its report. " Its functionality has been enhanced to allow the extraction of KeePass database data."
See also: Ransomware groups abuse legitimate Kickidler software
Specifically, when a KeePass database is opened, the application automatically exports the contents — account names, usernames, passwords, websites, and comments — to a CSV file , which is saved in %localappdata% with the extension .kp .
The attack investigated by WithSecure culminated in the successful installation of ransomware on the affected company's VMware ESXi servers, indicating that the KeeLoader infection was the starting point of a broader infrastructure-level attack.
Further investigation found an extensive infrastructure created to distribute malware disguised as legitimate tools and phishing pages designed to steal credentials.
The aenys[.]com was used to host additional subdomains that mimicked well-known platforms and businesses, such as WinSCP, Phantom Wallet, PumpFun, Sallie Mae, Woodforest Bank, and DEX Screener. Each subdomain was used to either distribute malicious payloads or steal credentials through phishing techniques.
According to WithSecure's analysis, this malicious activity is likely linked to the UNC4696 group.
See also: Hackers hide ransomware in JPG images

Security experts warn that even seemingly trustworthy ads can be traps. Threat actors are increasingly managing to bypass ad networksby displaying legitimate URLs that ultimately lead to malicious websites.
To avoid risks, it is recommended to download sensitive software only from the providers' official websites and avoid using links from advertisements or unverified sources.
As we mentioned earlier, the fake KeePass attack led to a ransomware attack. Organizations should take steps to protect themselves from this threat:
- Implement multi-factor authentication (MFA) for all user accounts
- Enable firewall on all devices connected to the network
- Encryption of sensitive data
- Updating devices and systems with the latest security patches
- Conducting regular security audits and penetration testing
- Using strong, unique passwords
- Limiting user access to only necessary systems and information
- Use solutions email security for additional protection against phishing attacks
- Recovery plan for quick recovery
Source: www.bleepingcomputer.com
