Fake LastPass installers deliver Rapuncel stealer, kernel driver

Malicious GitHub pages pushed fake LastPass installers that used a Microsoft-attested kernel driver to disable 145 security tools and install the Rapuncel stealer, LastPass researchers found.

LastPass researchers found fake LastPass installers hosted on GitHub that delivered a Microsoft-attested kernel driver and the Rapuncel information-stealing malware. The activity was discovered on August 13 and had been active for several months. Attackers impersonated at least 40 organizations and published multiple SEO-optimized GitHub pages, including one that ranked highly for searches of the legitimate LastPass Authenticator and another offering a fake macOS LastPass app.

Victims were routed through several GitHub pages and a Cloudflare-fronted server that allowed the operator to change the final destination dynamically. LastPass observed the server still issuing a JavaScript redirect as of September 10 and noted its content changed between August 27 and September 10. The final download page delivered an archive containing a fake installer, a malicious DLL and unrelated files.

The installer was a renamed Microsoft debugging tool that, when run, loaded a companion DLL containing attacker code. Analysis by LastPass links the DLL to the Cruciferra PUROSANGUE crypter package. The malicious loader and payload show behavioral and artifact overlaps with BoryptGrab; Delphos assessed Rapuncel as a BoryptGrab-related variant or sibling.

Rapuncel attempts to gain System privileges using built-in Windows features and installs a kernel driver that masquerades as an NVIDIA graphics component. The driver was written to locate and terminate 145 antivirus and endpoint security products, hide itself and inject a helper into running processes. In the samples observed, some killing and hiding functions did not activate because a required configuration file was missing, but the driver code documents the intended behavior.

After disabling protections, the stealer searches for saved passwords in 25 browsers, cryptocurrency files across about 30 wallet applications, Discord, Steam and Telegram tokens, the Windows credential store, and documents containing credential or wallet keywords. It takes screenshots of connected monitors and collects a detailed profile of the infected machine. The malware installs as a Windows service that starts at boot, repeatedly checks for security products, kills any that restart, and reruns the stealer.

In its report, LastPass wrote, “The malware installs itself as a Windows service that starts automatically every time the computer boots. It then loops continuously: checking for security products, killing any that have restarted, and re-running the stealer. The machine may remain fully under the attacker’s control until the kernel driver is physically removed.”

The investigation was conducted with Delphos. LastPass urged users to avoid downloading authenticator apps or installers from search results and to verify official sources. The company also recommended monitoring for signs of driver sideloading and unusual service installation and keeping endpoint protections and recovery procedures up to date.

Articles by this author