Closeup Photo of a Finger Pressing on the App Store Icon
© ymgerman/Shutterstock.com
No AI-generated content: this article is written and researched by humans
Table of contents

A fraudulent app designed to mimic the well-known password manager LastPass was found on Apple’s App Store this week.

In a blog post on Wednesday, LastPass said the app, called “LassPass Password Manager,” had an individual named Parvati Patel listed as its developer.

The fake LastPass app has since been taken down from the store. It’s unclear how long the app was on there, how it passed Apple’s notoriously strict review process, and how many people downloaded it.

Cybercriminals are known to create fake apps to swipe the data of unsuspecting victims. Installing the copycat LastPass app would have given threat actors access to login credentials for sensitive accounts like email, bank, cryptocurrency wallet, and more.

Upon discovering the app, LastPass initiated a comprehensive strategy involving its threat intelligence, legal, and engineering teams to have it taken down, Christofer Hoff, LastPass chief secure technology officer, told The Register on Thursday.

Fake LastPass App Had Many Red Flags

While the fake app was designed to imitate the branding and interface of LastPass, vigilant users would have spotted many red flags.

Besides the obvious misspelling in its name — “LassPass Password Manager” — the developer is different from that of the official LastPass app, LogMeIn, Inc.

While the LastPass app currently has over 52 thousand ratings on the App Store, the imposter app had only a few reviews and a single app rating — all of which are major red flags. Unfortunately, many people overlook these details when downloading apps.

In response to complaints about the fake LastPass app, Apple has also expelled the developer from the Apple Developer Program, according to Bleeping Computer.

“Submitting apps which impersonate other apps or services is considered a violation of the Developer Code of Conduct and may result in removal from the Apple Developer Program,” Apple’s App Store Review Guidelines state.

Interestingly, there is still an app called “PRAJAPATI SAMAJ 42 GOR ABD-GNR” listed under the same developer on the App Store. It looks like a directory app for a small community that connects individuals, villages, and businesses.

LastPass said it will “continue to monitor for fraudulent clones of our applications and/or infringements” of its intellectual property. “[We’re] working with Apple to understand more broadly how an application like this passed their normally rigorous security and brand protection mechanisms,” Hoff added.

This is not the first time a fraudulent app has slipped past Apple’s defenses. In May 2023, Cybersecurity firm Sophos warned about bogus ChatGPT apps on the App Store and Google’s Play Store.

How to Spot Fake Apps

To avoid downloading fraudulent apps, we recommend only getting apps from official app stores or the app developer’s official website. Even then, be wary of misspellings and check the interface and design to see if everything looks right.

The chances of unwittingly downloading fraudulent apps on your iPhone or iPad will become more pronounced with the release of the iOS 17.4 update in March. The update will introduce the ability to “sideload” apps and use alternative app stores for the first time.

LastPass has lost its place in our best password manager rankings due to a series of security incidents in recent years. If you’re a LastPass user, we recommend keeping your app updated and keeping tabs on security directives from the company. Check out our LastPass review to learn all about the features, security, and performance of this service.

For more news, follow us on X (Twitter), Threads, and Mastodon!

Leave a comment