Bitwarden malvertising campaign (11-11-2025)

Google Search Ad

Google ad for Bitwarden

Traffic view

Traffic

Decoy page

Decoy page

Payload

Payload

VirusTotal

IOCs

Cloaking domain bitward[.]passesmanager[.]com
Decoy page birwarden[.]click
Payload URL genie[.]thecodelab[.]me/bitwarden_installer.exe
Payload SHA256 a4f34954f535cadba717ddd6b7eb75ca575bb40f60cb908155eead4ce8b4d7d5
Malvertising Research index