Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Ekurhuleni killings: Two charged with murder in South Africa over woman’s body in Dawn Park

    September 21, 2026

    22 countries back call to keep AI ‘under human control’ – POLITICO

    September 21, 2026

    Britain loves its underdogs. We should be celebrating our Eurovision flops, not investigating them | Zoe Williams

    September 21, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Ekurhuleni killings: Two charged with murder in South Africa over woman’s body in Dawn Park
    • 22 countries back call to keep AI ‘under human control’ – POLITICO
    • Britain loves its underdogs. We should be celebrating our Eurovision flops, not investigating them | Zoe Williams
    • Apple Mac Mini (M6) Review: For the AI Curious
    • Multi-agent AI systems are taking over supply chain execution
    • TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
    • Russian Crypto Industry Could Be Operating By Year-End
    • Arctic Melt Season Length Levels Off
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, September 21
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 21, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A fake LastPass Authenticator distributed via GitHub has led to the discovery of a broad impersonation campaign delivering infostealer malware, LastPass reports.

    As part of the campaign, the attackers impersonated at least 40 organizations to push a Microsoft-attested kernel driver designed to terminate 145 security tools and open the door to information-stealing malware called Rapuncel.

    Discovered on August 13, the fake LastPass lure represents opportunistic brand spoofing — with no internal LastPass systems compromised — and forms part of a campaign active for several months.

    Using SEO optimization, the attackers’ GitHub page serving the fraudulent LastPass Authenticator was shown among the top results to users searching for the legitimate application. Another page was offering a fake macOS LastPass application.

    The attackers used a hidden routing chain relying on multiple GitHub pages and a Cloudflare-fronted server to direct victims to the final destination, which could be changed by the operator dynamically.

    The server was still active and serving a JavaScript redirect as of September 10, but “its content had changed between August 27 and September 10, confirming active ongoing maintenance,” LastPass notes.

    Advertisement. Scroll to continue reading.

    Ultimately, the victim was taken to a download page serving an archive containing a fake installer, malicious file, and junk. When executed, the installer, a renamed version of Microsoft’s own debugging tool, would load a companion DLL containing the attacker’s code.

    The Rapuncel malware attempts to achieve System privileges via built-in Windows features, and installs a kernel driver posing as an NVIDIA graphics component that was designed to terminate 145 antivirus and endpoint security products.

    According to LastPass, the driver contains code to hide itself and inject a helper into every running process, but the observed iteration lacked the necessary configuration and did not activate the features.

    Once the security tools are shut down, the malware starts looking for saved passwords in 25 browsers, the cryptocurrency files of 30 wallet applications, Discord tokens, Steam tokens, Telegram data, the Windows credential store, and all documents containing credential and wallet keywords.

    Furthermore, Rapuncel takes a screenshot of every connected monitor and captures a detailed profile of the system, LastPass says.

    “The malware installs itself as a Windows service that starts automatically every time the computer boots. It then loops continuously: checking for security products, killing any that have restarted, and re-running the stealer. The machine may remain fully under the attacker’s control until the kernel driver is physically removed,” LastPass notes.

    The investigation into the campaign, performed in collaboration with Delphos, revealed a connection with Cruciferra, a crypter service recently detailed by Proofpoint, through the malicious DLL loaded during the infection chain.

     The DLL was likely produced using the Cruciferra package called PUROSANGUE, which was previously used to create other side-loaded DLLs that contained EDR/AV-killing code.

    Additionally, the campaign shows several overlaps with BoryptGrab, the information stealer that was distributed through roughly 100 GitHub repositories earlier this year.

    “Delphos compared the Rapuncel stealer payload directly against Trend Micro’s documented BoryptGrab samples. The two families are not byte-identical; however, the behavioral and artifact-level overlap is strong. Delphos assesses Rapuncel is a BoryptGrab-related variant or sibling build,” LastPass says.

    Related: RatHat Android Trojan Uses AI for Automation

    Related: Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems

    Related: In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

    Related: AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals

    EDR Fake installers KernelLevel Killer LastPass Push Rapuncel Stealer
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

    ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks

    Orchid Security Introduces AI Agent Readiness Controls Featuring Continuous Identity Monitoring and Kill-Switch Capabilities

    Microsoft: September updates break File History backup feature

    Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems

    ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Ekurhuleni killings: Two charged with murder in South Africa over woman’s body in Dawn Park

    September 21, 2026

    22 countries back call to keep AI ‘under human control’ – POLITICO

    September 21, 2026

    Britain loves its underdogs. We should be celebrating our Eurovision flops, not investigating them | Zoe Williams

    September 21, 2026

    Apple Mac Mini (M6) Review: For the AI Curious

    September 21, 2026
    Latest Posts

    Google Assistant will disappear from your phone next month

    August 5, 2026

    Pope Leo Will Visit Peru, Where He Lived for Years, in November

    August 5, 2026

    Forget the goals and PBs – just enjoy it | Sport

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Ekurhuleni killings: Two charged with murder in South Africa over woman’s body in Dawn Park

    September 21, 2026

    22 countries back call to keep AI ‘under human control’ – POLITICO

    September 21, 2026

    Britain loves its underdogs. We should be celebrating our Eurovision flops, not investigating them | Zoe Williams

    September 21, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.