A fake LastPass Authenticator distributed through GitHub was used in a long-running impersonation campaign that spoofed at least 40 organizations and delivered the Rapuncel infostealer. The malware deploys a kernel driver to disable security tools, steal passwords and wallet data, and persist on infected systems until the driver is removed. #LastPass #GitHub #Rapuncel #Cruciferra #BoryptGrab
Keypoints
- A fake LastPass Authenticator was promoted through SEO and GitHub pages.
- The campaign impersonated at least 40 organizations to lure victims.
- Rapuncel used a Microsoft-attested kernel driver to kill 145 security tools.
- The malware stole browser passwords, wallet files, tokens, and screenshots.
- The infection chain showed links to Cruciferra and BoryptGrab.
Read More: https://www.securityweek.com/fake-lastpass-installers-push-kernel-level-edr-killer-rapuncel-stealer/