Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
By [email protected] (The Hacker News)
AI Summary
A fake LastPass Authenticator installer hosted on GitHub deploys a Microsoft WHCP-signed kernel driver that terminates 145 security products — including antivirus and EDR solutions — before dropping the 'Rapuncel' infostealer, discovered by LastPass and Delphos Labs on September 17. The driver scored zero detections on VirusTotal at time of discovery, and the campaign impersonates at least 40 different companies to maximize victim reach. The abuse of Microsoft's hardware compatibility signing program to achieve kernel-level EDR evasion represents a serious escalation in attacker sophistication.
Relevance score: 91.0/100
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →