SecurityWeek

Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer


A fake LastPass Authenticator distributed via GitHub has led to the discovery of a broad impersonation campaign delivering infostealer malware, LastPass reports.

As part of the campaign, the attackers impersonated at least 40 organizations to push a Microsoft-attested kernel driver designed to terminate 145 security tools and open the door to information-stealing malware called Rapuncel.

Discovered on August 13, the fake LastPass lure represents opportunistic brand spoofing — with no internal LastPass systems compromised — and forms part of a campaign active for several months.

Using SEO optimization, the attackers’ GitHub page serving the fraudulent LastPass Authenticator was shown among the top results to users searching for the legitimate application. Another page was offering a fake macOS LastPass application.

The attackers used a hidden routing chain relying on multiple GitHub pages and a Cloudflare-fronted server to direct victims to the final destination, which could be changed by the operator dynamically.

The server was still active and serving a JavaScript redirect as of September 10, but “its content had changed between August 27 and September 10, confirming active ongoing maintenance,” LastPass notes.

Advertisement. Scroll to continue reading.

Ultimately, the victim was taken to a download page serving an archive containing a fake installer, malicious file, and junk. When executed, the installer, a renamed version of Microsoft’s own debugging tool, would load a companion DLL containing the attacker’s code.

The Rapuncel malware attempts to achieve System privileges via built-in Windows features, and installs a kernel driver posing as an NVIDIA graphics component that was designed to terminate 145 antivirus and endpoint security products.

According to LastPass, the driver contains code to hide itself and inject a helper into every running process, but the observed iteration lacked the necessary configuration and did not activate the features.

Once the security tools are shut down, the malware starts looking for saved passwords in 25 browsers, the cryptocurrency files of 30 wallet applications, Discord tokens, Steam tokens, Telegram data, the Windows credential store, and all documents containing credential and wallet keywords.

Furthermore, Rapuncel takes a screenshot of every connected monitor and captures a detailed profile of the system, LastPass says.

“The malware installs itself as a Windows service that starts automatically every time the computer boots. It then loops continuously: checking for security products, killing any that have restarted, and re-running the stealer. The machine may remain fully under the attacker’s control until the kernel driver is physically removed,” LastPass notes.

The investigation into the campaign, performed in collaboration with Delphos, revealed a connection with Cruciferra, a crypter service recently detailed by Proofpoint, through the malicious DLL loaded during the infection chain.

 The DLL was likely produced using the Cruciferra package called PUROSANGUE, which was previously used to create other side-loaded DLLs that contained EDR/AV-killing code.

Additionally, the campaign shows several overlaps with BoryptGrab, the information stealer that was distributed through roughly 100 GitHub repositories earlier this year.

“Delphos compared the Rapuncel stealer payload directly against Trend Micro’s documented BoryptGrab samples. The two families are not byte-identical; however, the behavioral and artifact-level overlap is strong. Delphos assesses Rapuncel is a BoryptGrab-related variant or sibling build,” LastPass says.

Related: RatHat Android Trojan Uses AI for Automation

Related: Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems

Related: In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

Related: AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals



Source link