
Leon Neal | Getty Images
Already aware of breaches in which partially encrypted login data fell into the hands of threat actors, LastPass found that the same attackers hacked into employees’ home computers, resulting in decryption available only to a handful of corporate developers. announced on Monday that it had obtained a vault that had been encrypted.
Although the initial intrusion into LastPass ended on August 12th, a major password manager spokesperson said the attackers began a “new series of reconnaissance, enumeration and exfiltration campaigns” between August 12th and August 26th. I was actively involved,” he said. An unknown attacker was able to steal valid credentials from a senior DevOps engineer and gain access to the contents of the LastPass data vault. Among other things, Vault provided access to a shared cloud her storage environment containing encryption keys for customer vault her backups stored in Amazon S3 buckets.
another bomb will drop
“This was accomplished by targeting the home computer of a DevOps engineer and exploiting a vulnerable third-party media software package, which enabled remote code execution capabilities, allowing the attacker to launch keylogger malware. Embedding is now possible,” wrote a LastPass representative. “The threat actor was able to obtain the employee’s master password entered into her LastPass corporate vault after the employee was authenticated with her MFA, and access the DevOps engineer’s her LastPass corporate vault.”
The hacked DevOps engineer was one of four LastPass employees with access to the corporate vault. Once in possession of the decrypted vault, the attackers contain “the decryption keys required to access AWS S3 LastPass production backups, other cloud-based storage resources, and several associated critical database backups.” Exported the entry.
Monday’s update comes after LastPass issued its last bomb update, which for the first time stated that, contrary to previous claims, attackers obtained customer vault data containing both encrypted and plaintext data. Two months later. LastPass then said the attackers also obtained a cloud storage access key and a dual storage container decryption key, allowing him to copy the customer’s vault his backup data from the encrypted storage container.
Backup data includes both unencrypted data such as website URLs and website usernames and passwords, secure notes, and form fill data with an additional layer of encryption using 256-bit AES was included. New details explain how the attacker obtained her S3 encryption key.
According to Monday’s update, the tactics, techniques and procedures used in the first case differed from those used in the second case, and as a result, it was not known to investigators that the two were directly related. was not apparent at first. In the second incident, the attackers used information obtained in the first incident to enumerate and exfiltrate data stored in S3 buckets.
“Although alerts and logs were enabled during these events, they were not immediately indicative of the anomalous behavior that was revealed in retrospect during our investigation,” a LastPass official wrote. . “Specifically, the threat actor was able to access his shared cloud storage environment using valid credentials stolen from a senior DevOps engineer. It was difficult to distinguish between legitimate activities within.”
LastPass learned of a second incident from Amazon’s warning about anomalous behavior when attackers attempted to use Cloud Identity and Access Management (IAM) roles to perform unauthorized activities.
The media software package exploited on the employee’s home computer was Plex, according to a person who was briefed about the private report from LastPass and spoke on condition of anonymity. Interestingly, Plex reported his own network intrusion on August 24th. This is just 12 days after the second incident began. The breach allowed the attackers to access a proprietary database and steal password data, usernames, and emails belonging to some of our 30 million customers. Plex is a leading provider of media streaming services that allow users to stream movies and audio, play games, and access their own content hosted on home or on-premises media servers.
Representatives for LastPass and Plex did not immediately respond to emails seeking comment on the matter.
The threat actors behind the LastPass breach have proven to be particularly resourceful, and the revelation that they managed to exploit a software vulnerability on an employee’s home computer further strengthens that view. As Ars advised in December, all LastPass users should change their master password and all passwords stored in their vaults. It’s not clear if an attacker has access to either, but precautions are warranted.