LastPass and Microsoft: Hackers Use Microsoft-Signed Driver to Disable 145 Security Tools and Steal Passwords

LastPass and Microsoft: Hackers Use Microsoft-Signed Driver to Disable 145 Security Tools and Steal Passwords

Sophisticated Malware Campaign Abuses Microsoft-Signed Driver to Disable Security Tools and Steal Data

Researchers from LastPass Threat Intelligence and Delphos Labs uncovered a malware campaign leveraging a Microsoft-attested Windows kernel driver to disable 145 antivirus and endpoint security processes before exfiltrating sensitive data. The operation, tracked as Rapuncel, impersonated LastPass Authenticator via fraudulent GitHub pages to distribute the malicious payload.

Attackers created a fake GitHub organization mimicking an official LastPass product page, complete with branding and SEO-optimized descriptions. Victims searching for "LastPass Authenticator download" were redirected through multiple GitHub Pages and Cloudflare-protected infrastructure before reaching attacker-controlled servers. The final payload was delivered as an oversized ZIP archive often exceeding 100 MB containing junk files to evade automated sandbox analysis.

The malware employed DLL side-loading via a renamed Microsoft debugging tool (vsdbg.exe) and a malicious vsdbg.dll, allowing execution under the guise of a legitimate Microsoft component. Once elevated, it deployed Alinubx.sys, a kernel driver disguised as nvfsflt64.sys and registered as the "NVIDIA File System Filter Driver." Despite its malicious functionality, the driver carried a valid Microsoft Windows Hardware Compatibility Publisher signature, enabling it to bypass security controls.

The driver contained 145 hardcoded process names, using kernel-level termination to disable antivirus and EDR tools including those protected by Windows Protected Process Light. Researchers linked the driver to the CnCrypt/CcProtect family, associated with Henan Dafeng Software, though it was not flagged in Microsoft’s vulnerable driver blocklist at the time of discovery.

After disabling security tools, Rapuncel targeted browser-stored passwords from over 25 browsers, including Chrome and Edge, via process injection to decrypt credentials. It also harvested cryptocurrency wallet files, Discord tokens, Steam sessions, Telegram data, Windows Credential Manager entries, screenshots, and documents containing keywords like "password" or "wallet." Stolen data was compressed into a ZIP file and exfiltrated to a command-and-control server at 2.26.126[.]50.

Key indicators of compromise include the NvFsFilter service, writes to C:\Windows\System32\drivers\vfsflt64.sys, and artifacts such as .\Alinubx, Alinubx.ccf, ProtectR3.dll, and Henan Dafeng Software in driver-signing metadata. Organizations are advised to monitor for renamed vsdbg.exe processes, unusual kernel driver loads, and large ZIP downloads from suspicious GitHub Pages. Systems executing the fake installer should be treated as fully compromised.

Source: https://cybersecuritynews.com/signed-driver-disable-security-tools-and-passwords/

Microsoft Threat Intelligence cybersecurity rating report: https://www.rankiteo.com/company/microsoft-threat-intelligence

LastPass cybersecurity rating report: https://www.rankiteo.com/company/lastpass

"id": "MICLAS1789993625",
"linkid": "microsoft-threat-intelligence, lastpass",
"type": "Cyber Attack",
"date": "5/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Users searching for LastPass '
                                              'Authenticator downloads',
                        'industry': 'Cybersecurity',
                        'name': 'LastPass',
                        'type': 'Company'}],
 'attack_vector': ['Fraudulent GitHub Pages',
                   'DLL Side-Loading',
                   'Kernel Driver Abuse'],
 'data_breach': {'data_exfiltration': 'Compressed into ZIP and sent to C2 '
                                      'server at *2.26.126[.]50*',
                 'file_types_exposed': ['ZIP',
                                        'Browser credential files',
                                        'Wallet files',
                                        'Documents'],
                 'personally_identifiable_information': 'Yes (credentials, '
                                                        'tokens, and sensitive '
                                                        'documents)',
                 'sensitivity_of_data': 'High (PII, financial, and '
                                        'authentication data)',
                 'type_of_data_compromised': ['Browser credentials',
                                              'Cryptocurrency wallet files',
                                              'Discord tokens',
                                              'Steam sessions',
                                              'Telegram data',
                                              'Windows Credential Manager '
                                              'entries',
                                              'Screenshots',
                                              'Documents with sensitive '
                                              'keywords']},
 'description': 'Researchers from LastPass Threat Intelligence and Delphos '
                'Labs uncovered a malware campaign leveraging a '
                'Microsoft-attested Windows kernel driver to disable 145 '
                'antivirus and endpoint security processes before exfiltrating '
                'sensitive data. The operation, tracked as *Rapuncel*, '
                'impersonated LastPass Authenticator via fraudulent GitHub '
                'pages to distribute the malicious payload.',
 'impact': {'brand_reputation_impact': 'Impersonation of LastPass '
                                       'Authenticator',
            'data_compromised': 'Browser-stored passwords, cryptocurrency '
                                'wallet files, Discord tokens, Steam sessions, '
                                'Telegram data, Windows Credential Manager '
                                'entries, screenshots, and documents '
                                "containing keywords like 'password' or "
                                "'wallet'",
            'identity_theft_risk': 'High (PII and credentials stolen)',
            'operational_impact': 'Disabling of 145 security processes, '
                                  'potential full system compromise',
            'payment_information_risk': 'High (cryptocurrency wallet files and '
                                        'credentials stolen)',
            'systems_affected': 'Windows systems with disabled antivirus/EDR '
                                'tools'},
 'initial_access_broker': {'backdoors_established': 'Malicious kernel driver '
                                                    '(Alinubx.sys)',
                           'entry_point': 'Fraudulent GitHub Pages '
                                          'impersonating LastPass '
                                          'Authenticator'},
 'investigation_status': 'Ongoing',
 'motivation': ['Data Theft', 'Credential Harvesting', 'Financial Gain'],
 'post_incident_analysis': {'root_causes': ['Abuse of Microsoft-signed kernel '
                                            'driver',
                                            'DLL side-loading via renamed '
                                            'Microsoft debugging tool',
                                            'Fraudulent GitHub Pages with SEO '
                                            'optimization']},
 'ransomware': {'data_exfiltration': 'Yes'},
 'recommendations': 'Monitor for renamed *vsdbg.exe* processes, unusual kernel '
                    'driver loads, and large ZIP downloads from suspicious '
                    'GitHub Pages. Treat systems executing the fake installer '
                    'as fully compromised.',
 'references': [{'source': 'LastPass Threat Intelligence and Delphos Labs'}],
 'response': {'enhanced_monitoring': 'Monitoring for renamed *vsdbg.exe* '
                                     'processes, unusual kernel driver loads, '
                                     'and large ZIP downloads from suspicious '
                                     'GitHub Pages',
              'third_party_assistance': 'LastPass Threat Intelligence and '
                                        'Delphos Labs'},
 'title': 'Sophisticated Malware Campaign Abuses Microsoft-Signed Driver to '
          'Disable Security Tools and Steal Data',
 'type': 'Malware Campaign',
 'vulnerability_exploited': 'Microsoft-signed kernel driver (Alinubx.sys) with '
                            'valid signature'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.