Skip to main content
See every side of every news story
Published loading...Updated

China-nexus actor steals thousands of documents in monthslong exploitation campaign

Researchers suspect the hacker employed LLMs to develop custom tools.

10 Articles

A fake LastPass Authenticator installer is being used in a sophisticated campaign to distribute malware capable of deactivating antivirus and EDR solutions in Windows. The attack combines fraudulent pages hosted in GitHub, SEO poisoning techniques, DLL lateral loading and exploitation of a vulnerable kernel driver for high privileges. The campaign analyzed by LastPass and Delphos Labs uses Rapuncel malware, an infostealer designed to steal crede…

A campaign that appeared to offer official tools from LastPass used fake repositories in GitHub to distribute Rapuncel, an infostealer capable of stealing credentials, sessions, crypto wallet data and sensitive documents. The operation also incorporated a signed controller that could terminate antivirus and EDR processes from kernel mode, turning a seemingly reliable download into a high-impact intrusion.

Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

Cybersecurity Dive broke the news in Washington, United States on Monday, September 21, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal