The record
Written from the 1 report below. Nothing here is unsourced.
- A fraudulent LastPass Authenticator installer hosted on GitHub installs a malicious kernel driver that terminates antivirus and EDR processes.
- This driver uses a technique known as bring your own vulnerable driver (BYOVD) to operate at a higher privilege level than security software.
- The malware then extracts saved browser passwords, cryptocurrency wallet files, and session tokens for various applications.
- Affected users should treat their systems as compromised and change all saved credentials from a secure device.
What to watch next
- Whether Microsoft adds the specific driver used to its vulnerable driver blocklist
- Identification of further brand impersonation pages linked to this attacker infrastructure
- Monitoring for new iterations of the Rapuncel stealer and Cruciferra crypter
Who said what2
Only words found exactly in the article are shown, attributed and linked to the line they came from.
LastPass
1 quote · 1 outlet
“none of its own systems, services, or customer vaults were touched, and that the attackers only borrowed its name.”
In the article
…17. Microsoft's own hardware-compatibility program signs the driver, scored zero detections on VirusTotal when researchers checked it in August, and was not on Microsoft's list of blocked drivers. LastPass says none of its own systems, services, or customer vaults were touched, and that the attackers only borrowed its name. The lure is a fake GitHub page (github.com/LastPass-Authenticator) that ranks in search results for terms like "LastPass Authenticator download" and looks like a real LastPass product page. Clicking the download button…
Delphos Labs
1 quote · 1 outlet
“Microsoft attestation proves a driver passed through a trust pipeline. It does not prove the driver is safe.”
In the article
…The Hacker News has covered before. The driver is signed through the Microsoft Windows Hardware Compatibility Publisher chain, with a signing date of March 2023, years before this campaign. As the researchers put it, " Microsoft attestation proves a driver passed through a trust pipeline. It does not prove the driver is safe. " The kill list is the only part of the driver that ran here. Its code can also hide files, inject into other programs, and reroute web traffic, but those need a configuration file the attackers did not include, so they…
Coverage1
All filed from India
Named United States · LastPass · CnCrypt · Cruciferra · Delphos Labs · GitHub · Henan Dafeng Software · Microsoft · Rapuncel
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
