Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer
Incidents: Fake LastPass installers deliver Rapuncel stealer via kernel driver that disables 145 security tools.
Deep Analysis and Expert Commentary
The attack chain begins with SEO-optimized GitHub pages impersonating LastPass Authenticator, redirecting through Cloudflare-fronted servers to deliver a malicious archive. The payload includes a renamed Microsoft debugging tool that loads a malicious DLL, achieving System privileges via Windows features. The kernel driver, masquerading as an NVIDIA component, terminates EDR/AV products before Rapuncel harvests credentials from 25 browsers, 30 wallet apps, and system stores. The malware's persistence mechanism—a Windows service—ensures continuous execution unless the driver is physically removed. Defenders should monitor for GitHub repositories mimicking legitimate software, scrutinize kernel driver loads, and implement application allowlisting to prevent execution of unsigned binaries.
Action Items
- Monitor GitHub for repositories impersonating legitimate software
- Implement application allowlisting to block unsigned binaries
- Scrutinize kernel driver loads, especially those masquerading as hardware components
Original Article Brief Intro
SecurityWeek · 2026-09-21 · Incidents: Fake LastPass installers deliver Rapuncel stealer via kernel driver that disables 145 security tools.
Related Terms and Notes
Malware Families
- Infostealer
- Rapuncel — An information stealer malware that targets credentials, wallets, and system data, delivered via fake LastPass installers.
- Rapuncel Stealer
Context Notes
- Cruciferra — A crypter service used to obfuscate malicious DLLs, linked to EDR/AV-killing functionality.
- EDR Evasion
- EDR Killer
- GitHub Spoofing
- Kernel Driver
- LastPass
- Rapuncel