Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fake LastPass Installer Uses Signed Driver to Bypass Security

Fake LastPass Installer Uses Signed Driver to Bypass Security

Posted on September 21, 2026 By CWS

A fraudulent LastPass Authenticator installer, available on GitHub, has been discovered to contain a Windows kernel driver that disables antivirus programs before initiating a password theft operation. This was reported by cybersecurity experts from LastPass and Delphos Labs on September 17.

How the Fake Installer Operates

The malicious software is disguised as a legitimate LastPass Authenticator download page on GitHub, which appears in search results for related queries. Upon clicking the download link, users are redirected through several GitHub pages to an attacker’s server, where a large ZIP file is served. This ZIP file includes a renamed Microsoft debugging tool, vsdbg.exe, and a malicious DLL file, vsdbg.dll. The installer employs a technique known as DLL side-loading to execute the attacker’s code, which seeks to obtain administrator privileges and install the kernel driver as a service.

The archives discovered varied in size, padded with extraneous files to evade detection by security scanners with file size limitations.

The Role of the Signed Driver

The driver, named Alinubx.sys by researchers, operates at the kernel level, beneath the reach of standard antivirus and endpoint detection and response (EDR) tools. It contains a list of 145 antivirus and security processes to terminate. This method, known as bring your own vulnerable driver (BYOVD), exploits a legitimately signed driver to gain elevated access.

The driver was signed via Microsoft’s Hardware Compatibility Publisher with a date of March 2023, long before this campaign began. Microsoft attestation only confirms that a driver passed through a trust process, not its safety. The attack’s effectiveness is enhanced because the driver, a modified version of CcProtect.sys, is not included in Microsoft’s vulnerable driver blocklist.

Implications for Affected Users

Users who executed the fake installer should consider all browser-saved passwords, cryptocurrency wallets, and login sessions as compromised. The stealer extracts and transmits data before disabling security software, making recovery challenging. It is advised to change passwords from a clean device and monitor account activity for unauthorized access.

The presence of this driver necessitates a thorough forensic examination or a complete system rebuild to ensure the machine’s security.

Detecting and Preventing Future Attacks

Security professionals are urged to focus on the driver’s behavior rather than static attributes, as attackers can alter file names. Indicators include the creation of a service as NvFsFilter, a driver file named nvfsflt64.sys, and signing details that reference Henan Dafeng Software. Community detection resources, such as LOLDrivers, offer identification methods, although these are susceptible to evasion through file modification.

The GitHub page impersonating LastPass was one of many used by attackers. According to LastPass, the server hosted pages mimicking at least 40 brands. Similar attacks have been documented, underscoring the need for vigilance and improved detection mechanisms.

The Hacker News Tags:antivirus bypass, Attestation, BYOVD, Cybersecurity, data theft, EDR, fake installer, GitHub scam, kernel driver, LastPass, Malware, Microsoft, password stealer, security breach, signed driver

Post navigation

Previous Post: Ransomware Exploits Active Directory for Disruption
Next Post: Google Faces €403 Million Fine for GDPR Breach on Location Data

Related Posts

Critical WooCommerce Vulnerability Exploited by Attackers Critical WooCommerce Vulnerability Exploited by Attackers The Hacker News
Malicious Browser Extensions Infect 722 Users Across Latin America Since Early 2025 Malicious Browser Extensions Infect 722 Users Across Latin America Since Early 2025 The Hacker News
Cryptomining Botnet Targets Over 1,000 ComfyUI Instances Cryptomining Botnet Targets Over 1,000 ComfyUI Instances The Hacker News
From MCPs and Tool Access to Shadow API Key Sprawl From MCPs and Tool Access to Shadow API Key Sprawl The Hacker News
Chinese Hackers Exploit Ivanti EPMM Bugs in Global Enterprise Network Attacks Chinese Hackers Exploit Ivanti EPMM Bugs in Global Enterprise Network Attacks The Hacker News
How Small Teams Can Secure Their Google Workspace How Small Teams Can Secure Their Google Workspace The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Massive Data Loss in 103 Seconds by AI Coding Agent
  • Google Fined €403M for GDPR Breaches in Location Data
  • AWS Swiftly Quarantines Exposed IAM Keys on GitHub
  • North Korean Cyber Campaign Targets 30,000 Devices for Crypto Theft
  • Google Faces €403 Million Fine for GDPR Breach on Location Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Massive Data Loss in 103 Seconds by AI Coding Agent
  • Google Fined €403M for GDPR Breaches in Location Data
  • AWS Swiftly Quarantines Exposed IAM Keys on GitHub
  • North Korean Cyber Campaign Targets 30,000 Devices for Crypto Theft
  • Google Faces €403 Million Fine for GDPR Breach on Location Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark