{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/lastpass-authenticator/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["LastPass Authenticator","LastPass (macOS installer)"],"_cs_severities":["high"],"_cs_tags":["infostealer","malware","persistence","defense-evasion","supply-chain"],"_cs_type":"advisory","_cs_vendors":["Microsoft","LastPass"],"content_html":"\u003cp\u003eSince at least August 2026, threat actors have conducted a broad brand-impersonation campaign using SEO-poisoning techniques on GitHub to distribute fake software installers, including fraudulent LastPass Authenticator and macOS LastPass applications. The campaign, which targets at least 40 organizations, relies on a complex redirect chain involving GitHub and Cloudflare to deliver malicious archives. Upon execution, the installer uses a side-loaded DLL to deploy a Microsoft-attested kernel driver disguised as an NVIDIA component. This driver is designed to terminate 145 different endpoint security and antivirus products. Once security defenses are neutralized, the 'Rapuncel' stealer module installs itself as a persistent Windows service to harvest browser credentials, cryptocurrency wallets, messaging tokens, and system profile data. Researchers have identified links between this campaign's DLL loaders and the Cruciferra crypter service, as well as behavioral overlaps with the BoryptGrab infostealer.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe victim performs a search engine query and navigates to an SEO-poisoned GitHub repository masquerading as a legitimate software provider.\u003c/li\u003e\n\u003cli\u003eThe victim clicks a download link that traverses a hidden routing chain via multiple GitHub pages and a Cloudflare-fronted server.\u003c/li\u003e\n\u003cli\u003eThe victim downloads a malicious archive containing a fake installer and a companion DLL, which acts as a side-loader for malicious code.\u003c/li\u003e\n\u003cli\u003eThe installer executes a renamed legitimate debugging tool, which triggers the side-loading of the companion DLL into memory.\u003c/li\u003e\n\u003cli\u003eThe attacker's code loads a Microsoft-attested kernel driver that hides itself and attempts to terminate 145 predefined security and antivirus processes.\u003c/li\u003e\n\u003cli\u003eThe malware installs itself as a Windows service to ensure persistence across system reboots.\u003c/li\u003e\n\u003cli\u003eThe Rapuncel module scans the file system for sensitive data, including cryptocurrency wallets, browser-stored passwords, and messaging tokens.\u003c/li\u003e\n\u003cli\u003eCaptured data and system profiles are exfiltrated to the attacker's infrastructure while the service remains active to monitor and re-kill any restarted security tools.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThis campaign poses a severe risk to corporate and personal data by disabling endpoint security protections to facilitate long-term unauthorized access. By targeting 40+ brands and 145 security products, the attackers aim to harvest high-value credentials, cryptocurrency, and session tokens from a wide victim base. Successful infection results in total system compromise, where the machine remains under attacker control until the kernel-level driver is manually removed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize detection and response efforts to identify unauthorized kernel driver loads and persistent service creation associated with this campaign.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor endpoint logs for the installation of unsigned or suspiciously named kernel drivers, particularly those attempting to spoof NVIDIA-related file paths.\u003c/li\u003e\n\u003cli\u003eEnable Sysmon or equivalent EDR telemetry to detect the execution of renamed debugging tools (e.g., binaries performing DLL side-loading).\u003c/li\u003e\n\u003cli\u003eInspect GitHub-sourced software downloads for unauthorized or misaligned branding, especially when hosted outside of official vendor domains.\u003c/li\u003e\n\u003cli\u003eDeploy detection rules to identify new Windows services that lack verifiable developer signatures or that exhibit suspicious file paths in the ImagePath property.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-21T16:25:01Z","date_published":"2026-09-21T16:25:01Z","id":"https://feed.craftedsignal.io/briefs/2026-09-rapuncel-infostealer/","summary":"The Rapuncel infostealer campaign uses SEO-poisoned GitHub repositories to deliver malicious installers that deploy a kernel-level EDR killer to disable security products and harvest sensitive data.","title":"Rapuncel Infostealer Campaign Impersonates Software Brands","url":"https://feed.craftedsignal.io/briefs/2026-09-rapuncel-infostealer/"}],"language":"en","title":"CraftedSignal Threat Feed - LastPass Authenticator","version":"https://jsonfeed.org/version/1.1"}