A malware campaign is using SEO-optimized GitHub repositories to impersonate LastPass and dozens of other software firms in order to distribute the newly observed Rapuncel information stealer. The chain also installs the Alinubx.sys kernel driver, which is signed through Microsoft and can terminate 145 antivirus and EDR products while stealing credentials, browser data, and wallet information. #LastPass #DelphosLabs #Rapuncel #Alinubxsys #Microsoft
Keypoints
- SEO-optimized GitHub repositories impersonate trusted software brands to lure victims.
- The campaign distributes the previously undocumented Rapuncel infostealer.
- A Microsoft-signed driver, Alinubx.sys, is used to disable 145 antivirus and EDR tools.
- Victims are redirected through fake download pages to inflated ZIP archives containing the payloads.
- Rapuncel steals browser credentials, cryptocurrency wallet data, session tokens, screenshots, and system details.