Skip to main content

Geographic intelligence

Lithuania cybersecurity signals

Follow 1 current cybersecurity signal linked to Lithuania through an affected location, a profiled company's country, or both, with source reporting.

Affected-country links use structured victim-country data. Company-country links use a reviewed profile based on the organisation's headquarters or the local operating entity represented by its domain. A signal linked in both ways is counted once in the total; actor origin and locations inferred from prose remain excluded.

🇱🇹

Country context

About Lithuania

Reference details that help place the cybersecurity reporting in its geographic and economic context.

Region
Europe & Central Asia
Capital
Vilnius
Income group
High income
ISO codes
LT / LTU
ISO numeric
440

1

Total linked signals

Linked through an affected location, company headquarters, or both.

Not classified

Signals affecting this country

Victim-country data is unavailable in this reporting window.

1

Signals from companies based here

Based on reviewed company headquarters.

1

High or critical

Severity classifications among linked signals.

Company-linked signals

Current reporting linked to Lithuania

High

macOS CrashStealer Malware Targets NordPass User Data

A new macOS information stealer, identified as 'CrashStealer,' was reported on July 13, 2026. This malware is designed to harvest sensitive data from compromised macOS systems, specifically targeting credentials from 14 password managers, including NordPass, alongside browser data, cryptocurrency wallet extensions, and keychain material. The malware utilizes a signed and Apple-notarized dropper to bypass Gatekeeper checks, and exfiltrates the collected data to an attacker-controlled server. While NordPass's own systems were not breached, user data stored in NordPass could be compromised if a user's macOS device is infected with CrashStealer.

FAQ

Questions about Lithuania cybersecurity signals

What is included on the Lithuania page?

This page brings together current signals connected to Lithuania through an affected location, a reviewed company profile, or both.

Does a signal prove the attacker is based in Lithuania?

No. The country connection describes affected locations or profiled company locations. It does not claim actor origin unless a source explicitly establishes that separately.

Why can the number of signals change?

The page follows the rolling current-reporting window. Counts change as new incidents are added, evidence is reviewed, and older signals leave that window.