Researchers from LastPass and Delphos Labs have uncovered a sophisticated malware campaign utilizing a fake LastPass Authenticator installer hosted on GitHub. The attack employs DLL side-loading via a renamed Microsoft debugging tool to execute a malicious loader, which subsequently installs a Microsoft-signed kernel driver. This driver, identified as a renamed version of a legitimate disk-encryption tool, is used to terminate over 140 security processes, effectively bypassing antivirus and EDR solutions using the 'Bring Your Own Vulnerable Driver' (BYOVD) technique.
Once security defenses are neutralized, the campaign deploys a credential stealer dubbed 'Rapuncel.' This malware targets a broad spectrum of sensitive data, including browser-saved passwords from Chrome and Edge, cryptocurrency wallets, and session tokens for applications like Discord, Telegram, and Steam. Because the driver operates at the kernel level and persists through reboots, compromised machines require thorough forensic inspection or a complete rebuild to ensure the threat is fully eradicated.
Top comments (0)