Fake LastPass Installer on GitHub Uses Microsoft-Signed Driver to Kill 145 Security Tools
A fraudulent LastPass Authenticator installer hosted on GitHub deploys a malicious DLL that escalates privileges to SYSTEM level and installs a legitimate Microsoft-signed kernel driver called Alinubx.sys. The driver, operating below user-mode security layers, terminates 145 antivirus and endpoint detection processes before launching a credential stealer targeting browsers, crypto wallets, and Windows Credential Manager. LastPass and Delphos Labs published a joint analysis of the attack on September 17, noting the driver recorded zero detections on VirusTotal when tested in August and remains absent from Microsoft's vulnerable driver blocklist. The oversized installer archives, ranging from 128 MB to 148 MB, were padded with junk files to evade size-based scanning, and the attack exploited a classic DLL side-loading technique using a renamed Microsoft debugging tool. LastPass confirmed that its own systems, services, and customer vaults were not compromised, as attackers only impersonated the brand rather than breaching its infrastructure.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in