home.social

#logmein — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #logmein, aggregated by home.social.

fetched live
  1. I open the laptop's lid and it sprang to life. There on the desktop is the open #LogMeIn support chat app that he downloaded, allowed to run, and then gave it permission to control his computer remotely. There were other signs - two open terminals running with administrative privileges, browser settings that had been changed, etc.

    It was obvious he'd started by visiting some dodgy website and then allowing it to install a #browser #plugin. I found the installation date in a log. From there, it snowballed.

    It had installed some system-wide malware which disabled a bunch of security features and made cleanup tasks difficult - couldn't open Windows Defender, Task Manager was wonky, updates turned off, even installed some group policies to make it so you couldn't un-do those things from the regular settings panels.

    The final link in the chain was the system dialog that got him to phone in, and probably installed LogMeIn from there. I think the group behind it is called "YS" or similar. It had also dropped several suspicious executables in various places.

    It took me two hours to clear everything out and reset every change they'd made to the system, and then another half hour to lock the system down a bit by uninstalling non-essential features etc.

    There are federal holidays coming up in Canada and the USA that frequently result in big family gatherings. That would be an excellent time to check the computers of the hosts, if appropriate.

    2/x

  2. I open the laptop's lid and it sprang to life. There on the desktop is the open #LogMeIn support chat app that he downloaded, allowed to run, and then gave it permission to control his computer remotely. There were other signs - two open terminals running with administrative privileges, browser settings that had been changed, etc.

    It was obvious he'd started by visiting some dodgy website and then allowing it to install a #browser #plugin. I found the installation date in a log. From there, it snowballed.

    It had installed some system-wide malware which disabled a bunch of security features and made cleanup tasks difficult - couldn't open Windows Defender, Task Manager was wonky, updates turned off, even installed some group policies to make it so you couldn't un-do those things from the regular settings panels.

    The final link in the chain was the system dialog that got him to phone in, and probably installed LogMeIn from there. I think the group behind it is called "YS" or similar. It had also dropped several suspicious executables in various places.

    It took me two hours to clear everything out and reset every change they'd made to the system, and then another half hour to lock the system down a bit by uninstalling non-essential features etc.

    There are federal holidays coming up in Canada and the USA that frequently result in big family gatherings. That would be an excellent time to check the computers of the hosts, if appropriate.

    2/x

  3. Malspam sent from Microsoft Outlook that is spreading #LogMeIn GoToResolve RMM, enabling threat actors to access the victim's machine from remote 💻🔍🕵️

    IOCs:
    📡 adwestmailcenter .com ➡️ Landing page
    📡 insightme .im ➡️ fake PDF download

    Payload hosted on Cloudflare R2 bucket, but already got nuked due to an abuse report from URLhaus 🙌
    urlhaus.abuse.ch/url/3751500/

    LogMeIn #GoToResolve payload 📄
    bazaar.abuse.ch/sample/77e22f4

  4. Malspam sent from Microsoft Outlook that is spreading #LogMeIn GoToResolve RMM, enabling threat actors to access the victim's machine from remote 💻🔍🕵️

    IOCs:
    📡 adwestmailcenter .com ➡️ Landing page
    📡 insightme .im ➡️ fake PDF download

    Payload hosted on Cloudflare R2 bucket, but already got nuked due to an abuse report from URLhaus 🙌
    urlhaus.abuse.ch/url/3751500/

    LogMeIn #GoToResolve payload 📄
    bazaar.abuse.ch/sample/77e22f4

  5. I canceled #lastpass premium years ago (while they were part of #logmein), then they spun off or something and guess what - my premium subscription was reinstated 😡

    I've successfully had the charges refunded by my CC at least 2 years now and the charge appeared again for this year.

    I signed into LastPass and sure enough, a premium subscription was again associated with my account. I canceled it - again.

    Did LastPass send me a cancellation confirmation email? No. Is there a way for me to

    1/2

  6. I canceled #lastpass premium years ago (while they were part of #logmein), then they spun off or something and guess what - my premium subscription was reinstated 😡

    I've successfully had the charges refunded by my CC at least 2 years now and the charge appeared again for this year.

    I signed into LastPass and sure enough, a premium subscription was again associated with my account. I canceled it - again.

    Did LastPass send me a cancellation confirmation email? No. Is there a way for me to

    1/2

  7. #Bitwarden is awesome. It's FOSS, has all the features you could want, and it's free. I still pay for it just to support the development though. I have gotten my family to switch over too, after all the LastPass security breaches.

    I switched from #LastPass a few years ago right after they were bought by #Logmein. They had not had all the security blunders yet, but LogMeIn still had a history of being an awful company. I wanted nothing to do with them.

    pcworld.com/article/1655588/i-

  8. #Bitwarden is awesome. It's FOSS, has all the features you could want, and it's free. I still pay for it just to support the development though. I have gotten my family to switch over too, after all the LastPass security breaches.

    I switched from #LastPass a few years ago right after they were bought by #Logmein. They had not had all the security blunders yet, but LogMeIn still had a history of being an awful company. I wanted nothing to do with them.

    pcworld.com/article/1655588/i-

  9. #GoTo (formerly #LogMeIn) is warning customers that threat actors who breached its development environment in November 2022 stole encrypted backups containing customer information and an encryption key for a portion of that data. This is relating to the Central and Pro product tiers stored in a third-party cloud storage facility: bleepingcomputer.com/news/secu | #databreach #infosec

  10. #GoTo (formerly #LogMeIn) is warning customers that threat actors who breached its development environment in November 2022 stole encrypted backups containing customer information and an encryption key for a portion of that data. This is relating to the Central and Pro product tiers stored in a third-party cloud storage facility: bleepingcomputer.com/news/secu | #databreach #infosec

  11. Are You On LastPass? Time To Look At Alternatives
    LastPass was the first password manager I was aware of. The premise was simple: Using a LastPass account, you could store your website credentials in a "vault" on
    medi-nerd.com/2023/01/08/are-y
    #Technology #1Password #AreYouOnLastPass?TimeToLookAtAlternatives #BitWarden #Dashlane #DonPezet #ITProTV #LastPass #LogMeIn #PasswordManager #SecurityNow #SteveGibson #Technado #Technology #TWiT

  12. Are You On LastPass? Time To Look At Alternatives
    LastPass was the first password manager I was aware of. The premise was simple: Using a LastPass account, you could store your website credentials in a "vault" on
    medi-nerd.com/2023/01/08/are-y
    #Technology #1Password #AreYouOnLastPass?TimeToLookAtAlternatives #BitWarden #Dashlane #DonPezet #ITProTV #LastPass #LogMeIn #PasswordManager #SecurityNow #SteveGibson #Technado #Technology #TWiT

  13. @zarchasmpgmr @epixoip @sc00bz Ahh, now I remember why *I* dropped them.

    Everyone was grateful when #LastPass saved #XMarks from insolvency, but they were a poor fit and barely did anything other that fix the occasional bug. Then LastPass was acquired by #LogMeIn (#GoTo considered harmful) as an even worse fit, LastPass’s breach troubles accelerated, and two years later they gave all of a month’s notice before shutting down XMarks.

  14. oh and I moved to #bitwarden after #lastpass price skyrocketed after being bought by #logmein
    It really is a great service and I am glad to pay money for it.
    bitwarden.com

  15. oh and I moved to #bitwarden after #lastpass price skyrocketed after being bought by #logmein
    It really is a great service and I am glad to pay money for it.
    bitwarden.com

  16. Investoren schnappen sich #Lastpass-Betreiber #Logmein für 4,3 Milliarden.
    Also ich hätte mehr als Bauchschmerzen, wenn meine Passwörter als Ware gehandelt würden.

    t3n.de/news/investoren-schnapp

  17. LogMeIn agrees to be acquired by Francisco Partners and Evergreen for $4.3B - LogMeIn announced this morning that it has agreed to be sold for $4.3 billion to affiliates of Franc... more: feedproxy.google.com/~r/Techcr #mergersandacquisitions #elliottmanagement #franciscopartners #fundings&exits #privateequity #evergreen #logmein #cloud #m&a #tc