Rapuncel Stealer Uses Signed Driver to Kill Security Tools
Fake LastPass GitHub installers deliver Rapuncel, which uses a Microsoft-signed driver to kill 145 security tools and steal credentials.
LastPass and Delphos Labs described a campaign tracked as Rapuncel that used fraudulent GitHub repositories impersonating LastPass Authenticator, and in some accounts other companies, to deliver padded ZIP installers. The malware side-loads a DLL next to a renamed copy of Microsoft's vsdbg.exe, obtains SYSTEM rights, and installs Alinubx.sys, a kernel driver signed through Microsoft's Windows Hardware Compatibility Publisher. That driver terminates 145 antivirus and EDR processes from kernel mode, bypassing user-mode checks and Protected Process Light, and it persists across reboots. Sources agree it is a renamed copy of the Chinese disk-encryption driver CcProtect.sys that was absent from Microsoft's vulnerable-driver blocklist; Cyber Security News and GBHackers attribute it to Henan Dafeng Software, while The Hacker News calls it a March 2023-signed rename of CnCrypt's driver. With defenses disabled, Rapuncel steals passwords from 25 or more browsers, cryptocurrency wallets, Discord, Steam, and Telegram sessions, and Windows Credential Manager, then exfiltrates a ZIP to a command-and-control server. LastPass said its systems and customer vaults were untouched. SecurityWeek reported at least 40 organizations targeted, while Security Affairs described a multi-stage malware-as-a-service kit that impersonated at least 40 companies.
- LastPass and Delphos Labs linked the Rapuncel infostealer to fake LastPass Authenticator pages on GitHub that served padded ZIP installers.
- The installer side-loads a DLL beside a renamed copy of Microsoft vsdbg.exe, reaches SYSTEM, and installs kernel driver Alinubx.sys.
- Alinubx.sys, signed by the Microsoft Windows Hardware Compatibility Publisher (The Hacker News says March 2023), kills 145 antivirus and EDR processes, bypasses Protected Process Light, and persists across reboots.
- The driver is a renamed CcProtect.sys and was not on Microsoft's vulnerable-driver blocklist; sources name the vendor as Henan Dafeng Software or CnCrypt.
- It steals data from 25+ browsers, cryptocurrency wallets, Discord, Steam, Telegram, and Windows Credential Manager, exfiltrated as a ZIP to a C2 server.
- LastPass said its systems and customer vaults were not compromised.
- SecurityWeek says at least 40 organizations were targeted; Security Affairs says a malware-as-a-service kit impersonated at least 40 companies.
Coverage timelineoldest first · each row is one article
- · 5d agoHackers Use Microsoft-Signed Driver to Disable 145 Security Tools and Steal Passwords
Cyber Security News· 78
Hackers are using a Microsoft-signed driver to disable 145 security tools and steal passwords via fake LastPass download pages on GitHub.
- · 5d agoNew Rapuncel Infostealer Abuses Microsoft-Signed Driver to Disable 145 Security Tools
GBHackers· 78
A new infostealer named Rapuncel uses a Microsoft-signed kernel driver to kill 145 security tools and steal data via fake GitHub repositories.
- · 5d ago