Back to Feed
MalwareSep 21, 2026

Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer

Fake LastPass installers deliver kernel-level EDR killer and 'Rapuncel' stealer malware.

Summary

Attackers are impersonating at least 40 companies, including LastPass, to distribute a kernel driver that disables 145 security products. This campaign, active for months, uses SEO-optimized GitHub pages and Cloudflare to lure victims into downloading a fake installer that loads the 'Rapuncel' infostealer. The malware then steals credentials from browsers, crypto wallets, and messaging apps, while also profiling the system.

Full text

A fake LastPass Authenticator distributed via GitHub has led to the discovery of a broad impersonation campaign delivering infostealer malware, LastPass reports. As part of the campaign, the attackers impersonated at least 40 organizations to push a Microsoft-attested kernel driver designed to terminate 145 security tools and open the door to information-stealing malware called Rapuncel. Discovered on August 13, the fake LastPass lure represents opportunistic brand spoofing — with no internal LastPass systems compromised — and forms part of a campaign active for several months. Using SEO optimization, the attackers’ GitHub page serving the fraudulent LastPass Authenticator was shown among the top results to users searching for the legitimate application. Another page was offering a fake macOS LastPass application. The attackers used a hidden routing chain relying on multiple GitHub pages and a Cloudflare-fronted server to direct victims to the final destination, which could be changed by the operator dynamically. The server was still active and serving a JavaScript redirect as of September 10, but “its content had changed between August 27 and September 10, confirming active ongoing maintenance,” LastPass notes.Advertisement. Scroll to continue reading. Ultimately, the victim was taken to a download page serving an archive containing a fake installer, malicious file, and junk. When executed, the installer, a renamed version of Microsoft’s own debugging tool, would load a companion DLL containing the attacker’s code. The Rapuncel malware attempts to achieve System privileges via built-in Windows features, and installs a kernel driver posing as an NVIDIA graphics component that was designed to terminate 145 antivirus and endpoint security products. According to LastPass, the driver contains code to hide itself and inject a helper into every running process, but the observed iteration lacked the necessary configuration and did not activate the features. Once the security tools are shut down, the malware starts looking for saved passwords in 25 browsers, the cryptocurrency files of 30 wallet applications, Discord tokens, Steam tokens, Telegram data, the Windows credential store, and all documents containing credential and wallet keywords. Furthermore, Rapuncel takes a screenshot of every connected monitor and captures a detailed profile of the system, LastPass says. “The malware installs itself as a Windows service that starts automatically every time the computer boots. It then loops continuously: checking for security products, killing any that have restarted, and re-running the stealer. The machine may remain fully under the attacker’s control until the kernel driver is physically removed,” LastPass notes. The investigation into the campaign, performed in collaboration with Delphos, revealed a connection with Cruciferra, a crypter service recently detailed by Proofpoint, through the malicious DLL loaded during the infection chain. The DLL was likely produced using the Cruciferra package called PUROSANGUE, which was previously used to create other side-loaded DLLs that contained EDR/AV-killing code. Additionally, the campaign shows several overlaps with BoryptGrab, the information stealer that was distributed through roughly 100 GitHub repositories earlier this year. “Delphos compared the Rapuncel stealer payload directly against Trend Micro’s documented BoryptGrab samples. The two families are not byte-identical; however, the behavioral and artifact-level overlap is strong. Delphos assesses Rapuncel is a BoryptGrab-related variant or sibling build,” LastPass says. Related: RatHat Android Trojan Uses AI for Automation Related: Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems Related: In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw Related: AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire TigerByte Cyber Emerges From Stealth With $3 Million in FundingNightmareStresser DDoS Service Disrupted in International OperationBrevo Supply Chain Attack Injects Malware Into 100,000 WebsitesCritical Orkes Conductor Vulnerability Exploited in AttacksMIND Secures $72 Million for AI-Powered DLPRevolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M RansomComp AI Raises $34 Million for AI-Native Compliance and SecurityISC Patches 14 Vulnerabilities in BIND 9 Security Update Latest News CISO Conversations: Noopur Davis – The Accidental Global CISO at ComcastDragos Completes NetRise and runZero Acquisitions Following Accenture DealRatHat Android Trojan Uses AI for AutomationRust Team Members and Popular Crate Owners Targeted via Video CallsCrowdSec Confirms Source Code Stolen in Supply Chain AttackColorado Water Utilities Hit by Cyberattacks Targeting OT SystemsOrganizations Warned of 3 Exploited Linux Kernel VulnerabilitiesGoogle Confirms Gemini AI Breached Three Firms Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveVeritas Capital has appointed Joel Fulton as Chief Information Security Officer.incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.Ruben D. Chacon has joined ADM as Vice President and Global CISO.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • malware — Rapuncel
  • malware — BoryptGrab
  • malware — Cruciferra

Entities

LastPass Authenticator (product)LastPass (product)Microsoft (vendor)EDR (technology)GitHub (technology)