Rapuncel Malware Uses Signed Kernel Driver to Kill EDR Tools via Fake GitHub Repos
A Malware-as-a-Service campaign dubbed Rapuncel has been distributing infostealer malware through SEO-optimized fake GitHub repositories impersonating over 40 legitimate companies. Victims searching for software are lured into downloading oversized ZIP files hosted via GitHub Pages, which contain a fake installer that side-loads a malicious DLL into a legitimate Microsoft debugger process to gain SYSTEM privileges. A signed kernel driver, Alinubx.sys, is then deployed to terminate 145 security-related processes — including antivirus and EDR tools — from kernel mode, effectively blinding endpoint defenses. Rapuncel proceeds to steal credentials from browsers, cryptocurrency wallets, Discord, Steam, Telegram, and Windows Credential Manager, exfiltrating data to a remote server. Persistence is maintained through a registered Windows service that continues disabling security tools and harvesting data after system reboots.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in