Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
A fake LastPass Authenticator installer on GitHub delivered a signed Windows kernel driver that disabled security tools before a password stealer harvested credentials, wallet files, and session data. Researchers said the campaign used DLL side-loading, BYOVD tactics, and impersonation pages for many brands, while LastPass confirmed its own systems were not compromised. #LastPass #Alinubx.sys #CnCrypt #Cruciferra #BoryptGrab

Keypoints

  • A fake GitHub page posed as a LastPass Authenticator download.
  • The installer side-loaded a malicious DLL and installed a kernel driver.
  • The driver killed 145 security processes from kernel mode.
  • The stealer collected browser passwords, wallet files, and session data.
  • Microsoft’s driver blocklist did not yet include the abused driver.

Read More: https://thehackernews.com/2026/09/fake-lastpass-authenticator-installer.html