Home / Sep 22, 2026 / Story
0
#2 The Hacker News general September 21, 2026 at 17:31 UTC

Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

By [email protected] (The Hacker News)

AI Summary

A fake LastPass Authenticator installer hosted on GitHub deploys a Microsoft WHCP-signed kernel driver that terminates 145 security products — including antivirus and EDR solutions — before dropping the 'Rapuncel' infostealer, discovered by LastPass and Delphos Labs on September 17. The driver scored zero detections on VirusTotal at time of discovery, and the campaign impersonates at least 40 different companies to maximize victim reach. The abuse of Microsoft's hardware compatibility signing program to achieve kernel-level EDR evasion represents a serious escalation in attacker sophistication.

Relevance score: 91.0/100

# More from September 22