This fake LastPass Authenticator app will just shut off your antivirus and leave you open to attack
LastPass said the impostor app delivered Rapuncel, which can kill 145 security products and steal passwords, wallets, tokens and screenshots.
- Researchers from Delphos and LastPass identified a new infostealer named Rapuncel that uses DLL sideloading to disable 145 endpoint security and antivirus products.
- To distribute the malware, attackers used SEO poisoning to impersonate the LastPass Authenticator, hosting malicious ZIP files on GitHub pages that redirect users searching for "LastPass Authenticator download."
- Once active, Rapuncel installs a kernel driver disguised as an NVIDIA graphics component to gain SYSTEM-level access and steal passwords from more than 25 browsers and cryptocurrency wallet files from more than 30 applications.
- The malware establishes persistence by running as a Windows service that automatically starts at boot, requiring users to boot into Safe Mode or use external recovery tools for removal.
- Delphos and LastPass stressed this "opportunistic brand impersonation" has been active for months and will likely continue even after current infrastructure is burned, though customer vaults remain unaffected.
14 Articles
14 Articles
Microsoft-Signed Kernel Driver in Fake LastPass Authenticator Silences Defenses Before Password Theft
Attackers used a Microsoft-signed kernel driver in fake LastPass Authenticator downloads from GitHub to terminate 145 security tools from Ring 0. The Rapuncel stealer then harvested browser passwords, crypto wallets and session tokens while persisting as a service. LastPass confirmed no internal compromise occurred. Organizations must now rethink trust in signed drivers.
China-nexus actor steals thousands of documents in monthslong exploitation campaign
Researchers suspect the hacker employed LLMs to develop custom tools.
A fake installer of LastPass Authenticator, distributed via GitHub, installs Rapuncel, an infostealer that steals numerous data from the computer.
Fake LastPass Authenticator Installs a Microsoft-Signed Driver That Kills 145 Security Tools
TL;DR what: A fake LastPass Authenticator installer on GitHub side-loads a malicious DLL, escalates to SYSTEM, and installs a Microsoft-signed kernel driver named Alinubx.sys that terminates 145 antivirus and EDR processes before running a credential stealer. A fake LastPass Authenticator installer distributed through GitHub installs a Microsoft-signed Windows kernel driver that terminates 145 named antivirus and EDR processes, then runs a crede…
China-nexus actor steals thousands of documents in monthslong exploitation campaign | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker - National Cyber Security Consulting
A Chinese-speaking threat actor has engaged in a hacking campaign at least since June, involving the theft of thousands of documents from, at minimum, one Western government, according to a Monday blog post from threat intelligence firm GreyNoise. The hacker targeted critical vulnerabilities in multiple technologies, including WordPress, Zyxel and Ubiquiti, and is suspected of […] Thank you for subscribing to our RSS feed!
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium









