Back to advisories

Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer

Attackers are distributing fake installers impersonating 40+ companies including LastPass via SEO-poisoned GitHub pages to deliver a kernel-mode EDR killer and infostealer. The malware disables 145 known security products and exfiltrates credentials from browsers, crypto wallets, and messaging apps. Any user who downloaded what they thought was legitimate software may be fully compromised with security tools disabled.

CRITICALAdvisorySep 22, 2026
Action required
Hunt for unsigned kernel drivers loaded in the past 90 days, especially those matching known EDR killer signatures. Cross-reference with browser history for fake LastPass installer downloads from GitHub and similar distribution sites. Assume full credential compromise for any affected systems and reset passwords for critical accounts.
Affected products
LastPass AuthenticatorLastPassMicrosoft