Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
AI Summary
A malicious fake LastPass Authenticator installer distributed via a spoofed GitHub repository uses DLL side-loading to execute a malicious payload that disables antivirus and EDR solutions by loading a Microsoft-signed kernel driver. The driver, named Alinubx.sys, is a renamed version of the known CcProtect.sys driver from CnCrypt, signed through Microsoft's Windows Hardware Compatibility Publisher program. Once loaded, it terminates over 140 security processes from kernel mode, enabling a password stealer—identified as Rapuncel, related to BoryptGrab—to harvest credentials from browsers, cryptocurrency wallets, and messaging apps. The malware evades detection by renaming a known vulnerable driver, bypassing VirusTotal and Microsoft's driver blocklist due to hash changes.
AI-extracted · verify before operational use