China-nexus actor steals thousands of documents in monthslong exploitation campaign
6 Articles
6 Articles
China-nexus actor steals thousands of documents in monthslong exploitation campaign
Researchers suspect the hacker employed LLMs to develop custom tools.
A campaign that appeared to offer official tools from LastPass used fake repositories in GitHub to distribute Rapuncel, an infostealer capable of stealing credentials, sessions, crypto wallet data and sensitive documents. The operation also incorporated a signed controller that could terminate antivirus and EDR processes from kernel mode, turning a seemingly reliable download into a high-impact intrusion.
Hackers Use Microsoft-Signed Driver to Disable 145 Security Tools and Steal Passwords
Researchers uncovered a malware campaign that used a Microsoft-attested Windows kernel driver to turn off 145 antivirus and endpoint security processes, then stole passwords, cryptocurrency wallet data, browser sessions, and other sensitive information. LastPass Threat Intelligence, Mitigation, and Escalation team, working with Delphos Labs, discovered the operation after attackers impersonated LastPass Authenticator through fraudulent GitHub pa…
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium




