Home News Fake LastPass Installers Used to Deploy Rapuncel Stealer and Disable Security Software
NewsSecurity

Fake LastPass Installers Used to Deploy Rapuncel Stealer and Disable Security Software

5

Fake LastPass Installers Used to Deploy Rapuncel Stealer and Disable Security Software

Cybercriminals are using fake LastPass applications to distribute a powerful information-stealing malware known as Rapuncel, while also deploying a kernel-level driver designed to disable security products.

The campaign, uncovered after researchers identified a fraudulent LastPass Authenticator application on GitHub, appears to have been operating for several months. Investigators found that the attackers impersonated at least 40 organizations as part of the wider operation.

Importantly, there is no indication that LastPass itself was compromised. Instead, attackers abused the company’s name and branding to make malicious software appear legitimate.

The attackers used search-engine optimization techniques to push fraudulent GitHub pages toward the top of search results when users searched for the legitimate LastPass Authenticator. A separate fake application targeting macOS was also identified.

Victims were directed through a series of GitHub pages and a Cloudflare-hosted server before eventually reaching a download page. The server’s destination could be changed by the attackers, allowing them to modify the campaign without replacing the entire infrastructure.

The downloaded archive contained what appeared to be an installer, along with a malicious file and other junk files. The installer was actually a renamed version of a legitimate Microsoft debugging tool. When executed, it loaded a malicious DLL containing the attackers’ code.

Rapuncel then attempted to obtain elevated privileges on the Windows system. One of its most concerning components was a kernel driver disguised as an NVIDIA graphics component.

The driver was designed to terminate 145 antivirus and endpoint security products, effectively removing defenses before the information-stealing operation began.

Researchers also discovered code designed to hide the driver and inject a helper component into running processes. However, the particular sample they analyzed did not contain the configuration necessary to activate those capabilities.

Once security defenses were disabled, Rapuncel searched for sensitive information across the infected computer. The malware targeted saved passwords from 25 web browsers, files belonging to 30 cryptocurrency wallet applications, Discord and Steam tokens, Telegram information, Windows credentials and documents containing keywords associated with passwords and cryptocurrency wallets.

The malware can also capture screenshots from every connected monitor and collect detailed information about the infected system.

Rapuncel establishes persistence by installing itself as a Windows service that automatically starts whenever the computer boots. It repeatedly checks whether security products have restarted and attempts to terminate them again.

According to investigators, this behavior can allow an infected system to remain under an attacker’s control until the malicious kernel driver is removed.

The investigation also uncovered a possible connection between the campaign and the Cruciferra crypter service. Researchers believe the malicious DLL may have been created using a Cruciferra package known as PUROSANGUE, which has previously been associated with DLLs designed to disable endpoint security software.

There are also similarities between Rapuncel and BoryptGrab, another information-stealing malware family previously distributed through numerous GitHub repositories. Although the two malware families are not identical, researchers found enough behavioral and artifact-level similarities to describe Rapuncel as a possible BoryptGrab-related variant or sibling build.

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles

NewsSecurity

Pentagon Personnel Database Breach Exposes Sensitive Data of Millions

Pentagon Personnel Database Breach Exposes Sensitive Data of Millions The U.S. Department...

Security

Unpatched OnePlus Vulnerabilities Let Malicious Apps Gain Root Access

Unpatched OnePlus Vulnerabilities Let Malicious Apps Gain Root Access Two unpatched vulnerabilities...

NewsSecurity

Critical cPanel Vulnerability Lets Hosting Accounts Execute Code as Root

Critical cPanel Vulnerability Lets Hosting Accounts Execute Code as Root A newly...

NewsSecurity

North Korean Cyber Campaign Compromises 30,000 Devices Through Fake Job Interviews

North Korean Cyber Campaign Compromises 30,000 Devices Through Fake Job Interviews A...