Suspicious LastPass Domain

Published on: 
January 1, 2023

Redirects to a cloned page with malicious download

We detected a suspicious LastPass-related domain at lastpass[.]shop which resolves to an unrelated, innocuous food wholesaler site, but contains complex redirects to a LastPass clone page offering a probable malicious download at lastpass[.]shop/en/

The suspicious lastpass[.]shop is registered with namecheap and protected by Cloudflare, compared to the legitimate lastpass[.]com site registered with Name and hosted on Akamai.

Additionally, the download offered at lastpass[.]shop is a zip containing multiple files 10x the size of the official LastPass exe download.

Related Content

SecuritySnacks
Cybersecurity Reading List - Week of 2026-08-17
Learn More
SecuritySnacks
SecuritySnack - Account Farmers and Sellers
Explore how account farmers exploit lax signup friction to inflate metrics and sell verified accounts. Discover key IOCs and mitigation strategies.
Learn More
SecuritySnacks
Scarcity Scams
Discover how scarcity scams exploit government service bottlenecks to commit wire fraud and identity theft. Learn the tactics behind fake fast-track portals.
Learn More