Malicious Fake LastPass Installer Uses Microsoft-Signed Driver to Bypass Security Controls
A malicious fake LastPass Authenticator installer uses a Microsoft-signed kernel driver to disable antivirus and EDR solutions, enabling a password-stealing payload to exfiltrate sensitive data from compromised systems. The attack leverages driver signing trust mechanisms and DLL side-loading to achieve persistence and evade detection.
A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17.
Microsoft's own hardware-compatibility program signs the driver, scored zero detections on VirusTotal when researchers
*** END OF TRANSMISSION ***