All Episodes

February 15, 2025 16 mins
Fake LastPass App on Apple App Store: How to Protect Your Credentials 
 
This episode discusses the recent discovery of a fake LastPass application, named "LassPass Password Manager", on the Apple App Store. The fraudulent app mimicked the branding and user interface of the real LastPass app. We'll explore how this fake app bypassed Apple's security review process, what you can do to avoid falling victim to similar scams, and the importance of app attestation. What Happened?
  • A fake password management app called "LassPass Password Manager" appeared on the Apple App Store.
  • The app was created by a developer named Parvati Patel.
  • It imitated the original LastPass logo and user interface.
  • The purpose of the app was likely to steal credentials, including ID numbers, passwords, and crypto seed phrases.
  • The fake app was removed from the Apple App Store on February 8.
How Did This Happen?
  • The fake app used a similar name and logo to the real LastPass app, with only minor differences that may have been enough to evade automated detection.
  • The developer account appeared legitimate at first glance, but may have been compromised or used intentionally for malicious purposes.
  • Manual review oversight: Misspellings and a mismatched developer name were overlooked.
  • The app included a "PRO" subscription model.
How to Avoid Typosquatting and Fake Apps:
  • Click the app URL on the original author’s website. LastPass has links to the original app on their website.
  • Pay more attention to social proof. Look at metrics like date added, number of downloads, version history, and reviews.
  • Check the app details. Look for typos, incomplete app descriptions, grammatical blunders, and the use of a business name as the app developer.
App Attestation as a Solution:
  • App attestation validates the integrity and authenticity of individual applications.
  • It verifies that the app's runtime environment hasn't been tampered with.
  • Solutions like Approov issue cryptographic tokens to verified apps, ensuring only genuine apps can interact with backend APIs.
  • App attestation offers a proactive approach to enhance mobile app security and protect APIs from being exploited by fraudulent apps.
  • It can be integrated with platform-specific tools like iOS App Attest and Google Play Integrity.
Links:
  • Galactic Advisors: https://www.galacticadvisors.com
  • Fraudulent App: https://apps.apple.com/us/app/lasspass-password-manager/id6473945355
  • Legitimate LastPass App: https://apps.apple.com/us/app/lastpass-password-manager/id324613447
  • Approov: https://approov.io
Keywords: LastPass, fake app, Apple App Store, LassPass, password manager, security, typosquatting, phishing, app attestation, Approov, Parvati Patel, malware, mobile security, data theft, cyber security, credentials, API security.
Mark as Played

Advertise With Us

Popular Podcasts

Las Culturistas with Matt Rogers and Bowen Yang

Las Culturistas with Matt Rogers and Bowen Yang

Ding dong! Join your culture consultants, Matt Rogers and Bowen Yang, on an unforgettable journey into the beating heart of CULTURE. Alongside sizzling special guests, they GET INTO the hottest pop-culture moments of the day and the formative cultural experiences that turned them into Culturistas. Produced by the Big Money Players Network and iHeartRadio.

On Purpose with Jay Shetty

On Purpose with Jay Shetty

I’m Jay Shetty host of On Purpose the worlds #1 Mental Health podcast and I’m so grateful you found us. I started this podcast 5 years ago to invite you into conversations and workshops that are designed to help make you happier, healthier and more healed. I believe that when you (yes you) feel seen, heard and understood you’re able to deal with relationship struggles, work challenges and life’s ups and downs with more ease and grace. I interview experts, celebrities, thought leaders and athletes so that we can grow our mindset, build better habits and uncover a side of them we’ve never seen before. New episodes every Monday and Friday. Your support means the world to me and I don’t take it for granted — click the follow button and leave a review to help us spread the love with On Purpose. I can’t wait for you to listen to your first or 500th episode!

Dateline NBC

Dateline NBC

Current and classic episodes, featuring compelling true-crime mysteries, powerful documentaries and in-depth investigations. Follow now to get the latest episodes of Dateline NBC completely free, or subscribe to Dateline Premium for ad-free listening and exclusive bonus content: DatelinePremium.com

Music, radio and podcasts, all free. Listen online or download the iHeart App.

Connect

© 2025 iHeartMedia, Inc.