Fake LastPass Installers Deploy Kernel-Level EDR Killer and Stealer
A campaign using fake LastPass installers disables endpoint security tools at the kernel level to deliver the Rapuncel infostealer.
SecurityWeek reports that attackers are distributing fake LastPass installers as part of a campaign that impersonates at least 40 companies. The malicious installers are designed to disable endpoint detection and response (EDR) tools before delivering their payload.
The malware includes a kernel-level EDR killer that targets 145 security products, giving it deep access to bypass protections. After disabling these defenses, the campaign drops an infostealer known as Rapuncel, which is used to harvest sensitive data from compromised systems.
The use of a kernel-level component and broad impersonation suggests a well-resourced operation aimed at evading enterprise security controls. Users should obtain software only from official sources and treat unsolicited installer files with caution.
Sources · 2
More in Security & Privacy
WordPress Click2Shell CSRF Flaw Could Let Attackers Run PHP Code
A newly disclosed cross-site request forgery vulnerability in WordPress Core, with a public proof-of-concept, can let attackers execute PHP on the server.
Film Torrents Carry New Malware, Victims Found in Kenya and Uganda
Cybercriminals are using popular movie torrents to distribute fresh malware, with confirmed infections in East Africa.
CrowdSec Breach: TanStack npm Attack Exposed 170 Private Repos
CrowdSec says an attacker used a former employee's still-active GitHub access to copy 170 private repositories, tracing the intrusion to the TanStack npm attack.
CISA Adds Three Exploited Linux Kernel Flaws to KEV Catalog
The agency's move signals active attacks and pressures federal agencies to patch quickly.