Fake LastPass on GitHub Led to an Infostealer That Killed 145 Security Tools
GitHub-based LastPass impersonation distributed 'Rapuncel' infostealer using a signed driver to kill 145 security tools.
Attackers impersonated LastPass on GitHub, distributing a fake authenticator that deployed an infostealer named 'Rapuncel'. The campaign used a Microsoft-signed kernel driver to disable 145 antivirus and EDR products before stealing credentials from browsers, crypto wallets, and other applications. LastPass and Delphos Labs identified this as a multi-stage malware-as-a-service operation that impersonated at least 40 different companies, with the driver being a renamed version of the known Chinese disk-encryption driver CcProtect.sys.