<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>LastPass (MacOS Installer) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/lastpass-macos-installer/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 21 Sep 2026 16:25:01 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/lastpass-macos-installer/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Rapuncel Infostealer Campaign Impersonates Software Brands</title><link>https://feed.craftedsignal.io/briefs/2026-09-rapuncel-infostealer/</link><pubDate>Mon, 21 Sep 2026 16:25:01 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-rapuncel-infostealer/</guid><description>The Rapuncel infostealer campaign uses SEO-poisoned GitHub repositories to deliver malicious installers that deploy a kernel-level EDR killer to disable security products and harvest sensitive data.</description><content:encoded><![CDATA[<p>Since at least August 2026, threat actors have conducted a broad brand-impersonation campaign using SEO-poisoning techniques on GitHub to distribute fake software installers, including fraudulent LastPass Authenticator and macOS LastPass applications. The campaign, which targets at least 40 organizations, relies on a complex redirect chain involving GitHub and Cloudflare to deliver malicious archives. Upon execution, the installer uses a side-loaded DLL to deploy a Microsoft-attested kernel driver disguised as an NVIDIA component. This driver is designed to terminate 145 different endpoint security and antivirus products. Once security defenses are neutralized, the 'Rapuncel' stealer module installs itself as a persistent Windows service to harvest browser credentials, cryptocurrency wallets, messaging tokens, and system profile data. Researchers have identified links between this campaign's DLL loaders and the Cruciferra crypter service, as well as behavioral overlaps with the BoryptGrab infostealer.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The victim performs a search engine query and navigates to an SEO-poisoned GitHub repository masquerading as a legitimate software provider.</li>
<li>The victim clicks a download link that traverses a hidden routing chain via multiple GitHub pages and a Cloudflare-fronted server.</li>
<li>The victim downloads a malicious archive containing a fake installer and a companion DLL, which acts as a side-loader for malicious code.</li>
<li>The installer executes a renamed legitimate debugging tool, which triggers the side-loading of the companion DLL into memory.</li>
<li>The attacker's code loads a Microsoft-attested kernel driver that hides itself and attempts to terminate 145 predefined security and antivirus processes.</li>
<li>The malware installs itself as a Windows service to ensure persistence across system reboots.</li>
<li>The Rapuncel module scans the file system for sensitive data, including cryptocurrency wallets, browser-stored passwords, and messaging tokens.</li>
<li>Captured data and system profiles are exfiltrated to the attacker's infrastructure while the service remains active to monitor and re-kill any restarted security tools.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>This campaign poses a severe risk to corporate and personal data by disabling endpoint security protections to facilitate long-term unauthorized access. By targeting 40+ brands and 145 security products, the attackers aim to harvest high-value credentials, cryptocurrency, and session tokens from a wide victim base. Successful infection results in total system compromise, where the machine remains under attacker control until the kernel-level driver is manually removed.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize detection and response efforts to identify unauthorized kernel driver loads and persistent service creation associated with this campaign.</p>
<ul>
<li>Monitor endpoint logs for the installation of unsigned or suspiciously named kernel drivers, particularly those attempting to spoof NVIDIA-related file paths.</li>
<li>Enable Sysmon or equivalent EDR telemetry to detect the execution of renamed debugging tools (e.g., binaries performing DLL side-loading).</li>
<li>Inspect GitHub-sourced software downloads for unauthorized or misaligned branding, especially when hosted outside of official vendor domains.</li>
<li>Deploy detection rules to identify new Windows services that lack verifiable developer signatures or that exhibit suspicious file paths in the ImagePath property.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>infostealer</category><category>malware</category><category>persistence</category><category>defense-evasion</category><category>supply-chain</category></item></channel></rss>