Hackers Use Microsoft-Signed Driver to Disable 145 Security Tools and Steal Passwords
Hackers are using a Microsoft-signed driver to disable 145 security tools and steal passwords via fake LastPass download pages on GitHub.
A malware campaign tracked as Rapuncel used a Microsoft-signed kernel driver (Alinubx.sys) to disable 145 antivirus and EDR processes before stealing passwords and sensitive data. Attackers created fake GitHub repositories impersonating LastPass Authenticator to distribute the malware via large ZIP archives. The signed driver, a renamed version of CcProtect.sys from Henan Dafeng Software, was not on Microsoft's vulnerable driver blocklist and allowed the malware to bypass security protections. The stolen data included browser credentials, cryptocurrency wallets, and chat tokens, which were exfiltrated to a C2 server.