hacker-news · Crawled Sep 21, 2026

Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

5 IoCs
Read original article ↗

AI Summary

A malicious fake LastPass Authenticator installer distributed via a spoofed GitHub repository uses DLL side-loading to execute a malicious payload that disables antivirus and EDR solutions by loading a Microsoft-signed kernel driver. The driver, named Alinubx.sys, is a renamed version of the known CcProtect.sys driver from CnCrypt, signed through Microsoft's Windows Hardware Compatibility Publisher program. Once loaded, it terminates over 140 security processes from kernel mode, enabling a password stealer—identified as Rapuncel, related to BoryptGrab—to harvest credentials from browsers, cryptocurrency wallets, and messaging apps. The malware evades detection by renaming a known vulnerable driver, bypassing VirusTotal and Microsoft's driver blocklist due to hash changes.

AI-extracted · verify before operational use

Indicators of Compromise 5 extracted

Type Value Detail
Filename vsdbg.exe Details →
Filename vsdbg.dll Details →
Filename nvfsflt64.sys Details →
Filename Alinubx.sys Details →
GitHub Repo github.com/LastPass-Authenticator Details →