Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

MacRumors

macrumors bot
Original poster
Apr 12, 2001
63,558
30,889


Popular password management app LastPass is warning customers about a fraudulent app that uses a similar name and icon to attempt to trick LastPass customers into using the fake app instead of the real app (via Bleeping Computer).

lasspass-fake-password-manager-app.jpg

The "LassPass Password Manager" app was somehow approved by Apple's App Store review team, even though it appears to clearly mimic the LastPass app. It doesn't use exactly the same icon and the name is a letter off, but the similarities could confuse some LastPass users.

It is unclear if the fake LassPass app is attempting to steal login information from users, but it does have options for adding passwords, email accounts, addresses, bank accounts, credit cards, debit cards, and more. It doesn't ask for a LastPass login of any kind, but it is possible that the developer can see information added to the app.

There is also a "PRO" upgrade that costs $1.99 per month, $9.99 per year, or $49.99 for a "lifetime" subscription, so the aim of the app may be collecting subscription money from customers. Either way, LastPass users should be aware of the fake app and should avoid it. At best it is aiming to steal money, and at worst, it is stealing passwords and credit card information.

Clone apps often make their way into the App Store, but the app impersonating LastPass is particularly concerning because it could be accessing sensitive information. It is not clear how an app mimicking one of the most popular password management apps was approved by Apple, and its discovery comes at a critical time for the company.

Apple has been promoting the safety and security of the App Store as it prepares to allow for alternate app marketplaces in the European Union, and allowing a fake password management app onto the App Store is not a good look.

LastPass contacted Apple to get the clone app removed from the App Store, and it was pulled at around 11:00 a.m. Pacific Time on February 8.
Apple removed the fraudulent LassPass app because it violated the App Store rule preventing copycat apps. The developer has also been removed from the Apple Developer Program and won't be able to submit future apps.

Article Link: Fake LastPass App Sneaks Past Apple's Review Team
 
Last edited:

till

macrumors regular
Dec 3, 2007
248
1,563
New York or Berlin
When you open the App Store in iOS 17.4, at least in the EU, you get a new message about how the App Store is wonderful and safe and secure and private. Really embarrassing time for this to happen. It's really easy for an app like this to steal your passwords unless Apple is doing a meticulous security audit, which they're clearly not.
 

needsomecoffee

macrumors 6502
May 6, 2008
436
952
Seattle
Apple, one of the most litigious companies, seems to ignore Trademark rights for all apps in its store. Search on any well known, trademarked, product name. There may be dozen(s) of fraud apps appearing before the true rights owner's app. But, as we found out in the EU process, Apple's only real concern is user safety. The whole process (EU and Apple) is just so self-interested. Caveat emptor. I hate the App Store, and on my Mac I ALWAYS look for ways to avoid it (e.g. buy from Affinity web site for all their great apps.)
 
Last edited:

I7guy

macrumors Nehalem
Nov 30, 2013
34,240
23,975
Gotta be in it to win it
When you open the App Store in iOS 17.4, at least in the EU, you get a new message about how the App Store is wonderful and safe and secure and private. Really embarrassing time for this to happen. It's really easy for an app like this to steal your passwords unless Apple is doing a meticulous security audit, which they're clearly not.
Yeah and imo this scenario can be expected to replay itself with abandon.
 
  • Like
Reactions: Mescagnus

Reverend Benny

macrumors 6502a
Apr 28, 2017
704
463
Europe
I can only imagine that Apple can provide a list of what users and devices that has downloaded the App an use any of the tools they do have to block the App.
They should be able to reach out to the users fairly quick to warn them that the downloaded software is fraudware.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.