New Rapuncel Infostealer Abuses Microsoft-Signed Driver to Disable 145 Security Tools
A new infostealer named Rapuncel uses a Microsoft-signed kernel driver to kill 145 security tools and steal data via fake GitHub repositories.
Researchers from LastPass and Delphos Labs uncovered the Rapuncel infostealer campaign, which abuses a legitimate Microsoft-signed kernel driver to terminate security software. Attackers used fake GitHub repositories impersonating LastPass and other companies to distribute the malware. Once installed, Rapuncel disables 145 security processes using a kernel driver (Alinubx.sys) signed by the Microsoft Windows Hardware Compatibility Publisher, then steals sensitive data from browsers, wallets, and system storage. The driver was linked to Henan Dafeng Software and was not on Microsoft's vulnerable driver blocklist.