Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
A fake LastPass Authenticator installer uses a Microsoft-signed driver to kill EDR, then steals passwords and wallets.
LastPass and Delphos Labs reported a fake LastPass Authenticator installer on GitHub that side-loads a malicious DLL beside a renamed copy of Microsoft's vsdbg.exe. After reaching SYSTEM, it installs Alinubx.sys, a March 2023 Microsoft-signed rename of CnCrypt's CcProtect.sys, which kills 145 antivirus and EDR processes from the kernel. An infostealer then takes passwords from more than two dozen browsers, cryptocurrency wallets, Discord, Steam, and Telegram sessions, plus Windows Credential Manager, and exfiltrates a ZIP. LastPass said its systems and customer vaults were untouched; the driver was still off Microsoft's vulnerable-driver blocklist at the September 17 report and persists across reboots.