Fake LastPass Campaign Spreads Rapuncel Infostealer and Disables Antivirus and EDR Tools

Views: 50 views

522/69 Tuesday, September 22, 2026

Security researchers have disclosed a campaign involving fake GitHub pages impersonating LastPass Authenticator and software from at least 40 organizations to trick users into downloading malicious installers. The attackers use SEO techniques to make the fake pages appear prominently in search results. Once the installer is executed, it deploys an information-stealing malware named Rapuncel along with a kernel driver capable of terminating up to 145 antivirus and Endpoint Detection and Response (EDR) processes, allowing the malware to operate without interference. LastPass confirmed that the campaign is an external brand impersonation effort and that no LastPass systems, services, or password vaults were compromised.

The attack uses large ZIP files padded with unnecessary data to help evade certain security scanning mechanisms. Inside is a file that appears to be a LastPass installer but is actually a renamed Microsoft debugging tool used to load an attacker-controlled DLL. The malware then attempts to escalate privileges to SYSTEM before installing a kernel driver disguised as an NVIDIA component to terminate security software processes. Once successful, Rapuncel collects data from web browsers, cryptocurrency wallets, Discord, Steam, Telegram, and Windows Credential Manager. It can also capture screenshots and search for documents that may contain credentials or cryptocurrency wallet information.

Users should download LastPass and other software only from official websites or authorized distribution channels and should not trust files simply because they are hosted on GitHub or appear near the top of search results. LastPass stated that GitHub is not an official distribution channel for LastPass Authenticator. If users have executed an installer associated with this campaign, they should assume that credentials stored on the affected device may have been exposed, change those credentials from another trusted device, and review related accounts for suspicious activity.

Source: https://www.securityweek.com/fake-lastpass-installers-push-kernel-level-edr-killer-rapuncel-stealer/