Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer

The attackers impersonate at least 40 companies and disable 145 security products to deploy infostealer malware.

Malware

A fake LastPass Authenticator distributed via GitHub has led to the discovery of a broad impersonation campaign delivering infostealer malware, LastPass reports.

As part of the campaign, the attackers impersonated at least 40 organizations to push a Microsoft-attested kernel driver designed to terminate 145 security tools and open the door to information-stealing malware called Rapuncel.

Discovered on August 13, the fake LastPass lure represents opportunistic brand spoofing — with no internal LastPass systems compromised — and forms part of a campaign active for several months.

Using SEO optimization, the attackers’ GitHub page serving the fraudulent LastPass Authenticator was shown among the top results to users searching for the legitimate application. Another page was offering a fake macOS LastPass application.

The attackers used a hidden routing chain relying on multiple GitHub pages and a Cloudflare-fronted server to direct victims to the final destination, which could be changed by the operator dynamically.

The server was still active and serving a JavaScript redirect as of September 10, but “its content had changed between August 27 and September 10, confirming active ongoing maintenance,” LastPass notes.

Advertisement. Scroll to continue reading.

Ultimately, the victim was taken to a download page serving an archive containing a fake installer, malicious file, and junk. When executed, the installer, a renamed version of Microsoft’s own debugging tool, would load a companion DLL containing the attacker’s code.

The Rapuncel malware attempts to achieve System privileges via built-in Windows features, and installs a kernel driver posing as an NVIDIA graphics component that was designed to terminate 145 antivirus and endpoint security products.

According to LastPass, the driver contains code to hide itself and inject a helper into every running process, but the observed iteration lacked the necessary configuration and did not activate the features.

Once the security tools are shut down, the malware starts looking for saved passwords in 25 browsers, the cryptocurrency files of 30 wallet applications, Discord tokens, Steam tokens, Telegram data, the Windows credential store, and all documents containing credential and wallet keywords.

Furthermore, Rapuncel takes a screenshot of every connected monitor and captures a detailed profile of the system, LastPass says.

“The malware installs itself as a Windows service that starts automatically every time the computer boots. It then loops continuously: checking for security products, killing any that have restarted, and re-running the stealer. The machine may remain fully under the attacker’s control until the kernel driver is physically removed,” LastPass notes.

The investigation into the campaign, performed in collaboration with Delphos, revealed a connection with Cruciferra, a crypter service recently detailed by Proofpoint, through the malicious DLL loaded during the infection chain.

 The DLL was likely produced using the Cruciferra package called PUROSANGUE, which was previously used to create other side-loaded DLLs that contained EDR/AV-killing code.

Additionally, the campaign shows several overlaps with BoryptGrab, the information stealer that was distributed through roughly 100 GitHub repositories earlier this year.

“Delphos compared the Rapuncel stealer payload directly against Trend Micro’s documented BoryptGrab samples. The two families are not byte-identical; however, the behavioral and artifact-level overlap is strong. Delphos assesses Rapuncel is a BoryptGrab-related variant or sibling build,” LastPass says.

Related: RatHat Android Trojan Uses AI for Automation

Related: Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems

Related: In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

Related: AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Veritas Capital has appointed Joel Fulton as Chief Information Security Officer.

incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.

Ruben D. Chacon has joined ADM as Vice President and Global CISO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.