Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Rapuncel malware can disable 145 security products

LastPass has warned about a malware campaign targeting people searching for the LastPass Authenticator app. The campaign uses a spoofed website, search-engine poisoning and DLL sideloading to deliver a malware loader called Rapuncel.

According to LastPass, victims may be directed to a GitHub page that resembles the genuine offering before being redirected to attacker-controlled infrastructure. A ZIP archive contains a renamed Microsoft debugging tool, vsdbg.exe, and the malicious vsdbg.dll.

Delphos researchers said Rapuncel can gain SYSTEM-level access, install a kernel driver disguised as an NVIDIA graphics component and terminate security software. The driver contains a hardcoded list of 145 antivirus and endpoint-security products.

The malware can steal saved passwords from more than 25 browsers, cryptocurrency-wallet files from more than 30 wallet apps, Discord login tokens, Steam session tokens, Telegram session data, Windows credential-store data, selected documents and screenshots from every connected monitor. It compresses the collected information into a ZIP archive and uploads it to an attacker-controlled server.

LastPass and Delphos believe the campaign has been active for months. They described it as opportunistic brand impersonation and said LastPass systems and customer vaults were not compromised. LastPass said it was one of 40 companies spoofed in the campaign.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.