Lukasz Olejnik, a security and privacy technology researcher who reviewed Passwork’s Russian and European websites upon OCCRP’s request, said these and other overlaps raise questions about the strength of the firewall between Passwork’s European and Russian shopfronts, and that the subject “warrants a review.”

“The EU/RU split as of today appears technically shallow,” Olejnik said, pointing to 517 lines of what he characterized as  “basically identical” installer script, which refers to the set of instructions that automates the deployment, configuration, and setup of software on a user’s device. 

When confronted with the synchronized timelines, Passwork CEO Muntyan denied that the Russian and Spanish companies actively coordinate software updates. But he acknowledged that because they share “ a common codebase origin,”  it is possible that the UAE entity Passwork FZ-LLC is delivering updates to multiple parties on a similar timeline.

Those updates are reviewed by Passwork Europe SL’s technical team before incorporation, he added.

Van den Berg, the security expert at the Clingendael Institute, noted that the overall opacity around Passwork and any connections to the software of its Russian counterpart should raise questions for clients about what level of uncertainty they are comfortable with.

Particularly when it concerns something as sensitive as “where the keys to your digital home lie,” he said.

The mechanism by which updates are pushed is of particular concern, because compromised or malicious software updates remain one of the most effective methods for hostile actors to penetrate otherwise secure networks.

“The update mechanism is the most elegant and hardest-to-detect attack vector: a single prepared update could selectively trigger a [password] vault dump at targets deemed of interest and then disappear completely without a trace,” said Donald Ortmann, a German security researcher who advises businesses on cybersecurity and provides risks training to IT professionals.

Ortmann pointed to the example of the 2019-2020 hack of the U.S. software company SolarWinds, one of the largest and most significant cyberattacks in history, where Russian operatives are believed to have infiltrated the company’s systems to inject a trojan horse code that was included in one of its software updates.

After the update had been pushed to SolarWinds’ clients, the attackers had access via a backdoor to infected computers, compromising the email systems of the U.S. Treasury Department and Department of Justice. 

As in many other countries, including the U.S., the Russian state has the authority to compel those under its jurisdiction, such as the Russian Passwork’s owners, to cooperate with national intelligence agencies in executing such intelligence operations. 

“Given the broad powers of the Russian security services, if such materials or source code were to become of interest to the FSB, there is a significant risk that state authorities could gain access to them through mechanisms provided for by law or through de facto mechanisms of state influence,” said Oleksandr Frolov, a Kyiv-based partner at the international law firm Kinstellar who specializes in sanctions and risk.

On its website, the Russian Passwork confirmed that “the product architecture, cryptographic algorithms, access control, and logging mechanisms have undergone all stages of detailed verification for compliance with the requirements of FSTEC Order No. 76 of June 2, 2020.”

Clients in the Dark

Muntyan told reporters Passwork Europe SL has never concealed information about the origins of Passwork’s software or its original developers.

Its servers are based in Europe, Muntyan said, adding that he didn’t immediately re-brand the product “so that existing customers wouldn’t be disrupted by a new design.” 

Yet for several of the software’s European users, Passwork’s Russian backstory came as a surprise.

OCCRP contacted around 30 apparent clients, including those advertised on Passwork’s European website and LinkedIn.