A sophisticated phishing campaign has been uncovered, where attackers are using a fake LastPass Authenticator installer to compromise Windows systems. The malicious program exploits a Microsoft-signed driver to disable antivirus and endpoint detection and response (EDR) software, effectively allowing the attackers to remain undetected on compromised machines.
The attack begins with a phishing email that tricks victims into downloading what appears to be a legitimate LastPass Authenticator installer. However, once installed, the malware uses a Microsoft-signed driver to inject code into the Windows kernel, granting it elevated privileges. This allows the attacker to disable popular antivirus software and EDR tools, including those from vendors like Kaspersky, Norton, and CrowdStrike.
The malicious driver, known as ” win32kfull.sys”, is signed by Microsoft and therefore trusted by Windows. This makes it difficult for security software to detect the malware, as it appears legitimate. The attackers then use this access to disable critical security features, such as firewall rules and intrusion detection systems. This creates a perfect environment for further attacks, allowing the attacker to maintain persistence on the compromised system.
The victims affected by this campaign are likely individuals who have been targeted by phishing emails. LastPass has not been breached or involved in the attack in any way. The company’s authenticator app remains unaffected and continues to function normally.
This attack highlights a significant vulnerability in Windows’ driver signing mechanism. Microsoft’s decision to sign the malicious driver allows it to bypass traditional security measures, making it an attractive tactic for attackers. This incident emphasizes the importance of user education and awareness in preventing phishing attacks. Even the most sophisticated security solutions can be rendered useless if users are tricked into installing malware.
To protect against this type of attack, users should exercise extreme caution when downloading software or responding to unsolicited emails. Verify the authenticity of any email or installer before proceeding, and ensure that all software is obtained from trusted sources. Additionally, keeping antivirus software up-to-date and running regular security scans can help detect and prevent similar attacks in the future.
Source: The Hacker News — 2026-09-21