Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer

Fake LastPass Installers Deliver Kernel-Level EDR Killer and Info-Stealer

A sophisticated impersonation campaign has been uncovered, using fake LastPass installers to distribute a malware known as Rapuncel, which targets security tools and steals sensitive information. The attackers’ tactics include brand spoofing, SEO optimization, and the use of cloud-based infrastructure to evade detection.

The campaign, which has been active for several months, involves impersonating at least 40 organizations, including LastPass itself, to trick users into downloading a Microsoft-attested kernel driver designed to terminate 145 security tools. This kernel driver is actually an EDR (Endpoint Detection and Response) killer, allowing the malware to evade detection by security software.

The fake LastPass installers are distributed through GitHub pages that have been optimized for search engine results, making them appear as legitimate downloads to unsuspecting users. The attackers use a complex routing chain involving multiple GitHub pages and a Cloudflare-fronted server to direct victims to the final destination, which can be changed dynamically by the operator.

Once installed, the Rapuncel malware attempts to gain System privileges using built-in Windows features, before installing a kernel driver posing as an NVIDIA graphics component. This driver is designed to terminate security products and inject a helper into every running process. While the observed iteration of the malware lacked necessary configuration, it did not activate the full range of its capabilities.

The malware then starts looking for sensitive information, including saved passwords in 25 browsers, cryptocurrency files from 30 wallet applications, Discord tokens, Steam tokens, Telegram data, and Windows credential store. It also captures a detailed profile of the system and takes a screenshot of every connected monitor. Furthermore, Rapuncel installs itself as a Windows service that starts automatically on each boot, allowing it to continuously scan for security products and kill them.

An investigation into the campaign revealed connections with Cruciferra, a crypter service used to create malicious DLLs, and BoryptGrab, an information stealer distributed through GitHub repositories earlier this year. The similarities between Rapuncel and BoryptGrab are striking, suggesting that they may be variants of the same malware family.

This campaign highlights the importance of vigilance when it comes to brand spoofing and the use of cloud-based infrastructure to evade detection. Users should exercise extreme caution when downloading software from unknown sources or clicking on links in emails or online searches. It is also essential for organizations to stay up-to-date with the latest security patches and tools, as well as implement robust threat intelligence capabilities to detect and respond to emerging threats.

As a result of this campaign, users should be aware of the following:

* Be cautious when downloading software from unknown sources, especially if it appears too good (or legitimate) to be true.

* Verify the authenticity of the software by checking for official branding, logos, and contact information.

* Keep your operating system and security tools up-to-date with the latest patches and updates.

* Implement robust threat intelligence capabilities to detect and respond to emerging threats.

By being aware of these tactics and taking proactive steps to secure their systems, users can reduce the risk of falling victim to this type of campaign.


Source: SecurityWeek — 2026-09-21