Fake LastPass GitHub Repositories Push Rapuncel Malware to Windows Users
Rapuncel malware campaign uses fake GitHub repositories to target Windows users by impersonating LastPass and at least 39 other companies through SEO-optimized GitHub pages.
Researchers from LastPass and Delphos Labs found that the attackers target people searching for popular software, including LastPass Authenticator, and direct them to convincing fake repositories.
Fake GitHub downloads install Rapuncel
Download buttons on the malicious repositories send users through several redirects before delivering ZIP archives hosted on attacker-controlled servers.
The installer abuses Microsoft’s legitimate Visual Studio CoreCLR Debugger, vsdbg.exe, to sideload a malicious vsdbg.dll file. This process installs the Rapuncel infostealer alongside the Alinubx.sys kernel driver.
Microsoft-signed driver can disable security tools
Alinubx.sys disguises itself as an NVIDIA component called nvfsflt64.sys and registers as the NvFsFilter Windows service.
According to LastPass, the driver can terminate processes linked to 145 antivirus and EDR products from kernel mode. Researchers say it can potentially bypass Protected Process Light protections used by security software.
The driver carries a signature through Microsoft’s Windows Hardware Compatibility Publisher chain and, according to the researchers, does not currently appear on Microsoft’s vulnerable driver blocklist.
Rapuncel targets passwords, wallets, and sessions
Once security software stops running, Rapuncel attempts to steal credentials from 25 browsers, data from 30 cryptocurrency wallets, Windows Credential Manager information, and Discord, Steam, and Telegram sessions.
It also searches for files containing terms such as password, seed, wallet, and recovery. The malware can capture screenshots from every connected monitor and collect detailed system information.
Rapuncel also attempts to bypass Google’s App-Bound Encryption protection in Chrome, Edge, and related browsers.
The malware creates a Windows service for persistence, allowing it to restart after a reboot and terminate security software again. It then compresses stolen data and sends it to an external endpoint.
Researchers recommend downloading software only from official vendor websites and treating unfamiliar GitHub repositories and promoted search results with caution.
In other security news, OpenAI reveals AI models tried to conceal errors and hackers are mass-scanning Vite servers to steal AWS and Azure credentials.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages