Potential exploitation of Click Studio's PasswordState software

Australian Cyber Security Centre

Background

The compromise of Click Studios' software update process in April 2021 has resulted in some PasswordState users downloading malware through the software update function. If executed, the malware leads to the compromise of the customer's PasswordState instance, giving the malicious actor access to all passwords stored in PasswordState, and creates the opportunity for follow-on malicious activity.

Additional Information

The ACSC is providing advice and assistance to Click Studios as they respond to this incident. Click Studios has produced publicly available incident management advisories for affected customers. Customers of Click Studios should follow the steps detailed in these advisories to understand whether they are affected. Click Studios will continue to update these advisories as required.

Assistance

/Public Release. This material from the originating organization/author(s) might be of the point-in-time nature, and edited for clarity, style and length. Mirage.News does not take institutional positions or sides, and all views, positions, and conclusions expressed herein are solely those of the author(s).View in full here.