A deceptive version of the LastPass Authenticator distributed via GitHub has unveiled a widespread impersonation campaign aimed at disseminating information-stealing malware, according to reports from LastPass.
Impersonation Campaign Tactics
The attackers behind this scheme have impersonated over 40 organizations to distribute a Microsoft-certified kernel driver. This driver is engineered to disable 145 security tools, paving the way for a malicious program known as Rapuncel.
First identified on August 13, the fraudulent LastPass application demonstrates strategic brand spoofing. Importantly, no internal systems of LastPass were compromised. The campaign has been active for several months, leveraging SEO techniques to ensure the attackers’ GitHub page appeared prominently in search results for the legitimate application. Another page was misleadingly offering a fake macOS version of LastPass.
Technical Details of the Attack
To divert victims, the attackers employed a concealed routing chain using multiple GitHub pages and a server masked by Cloudflare, allowing dynamic control over the final destination. As of September 10, the server was operational, with changes in content observed between August 27 and September 10, indicating ongoing management, LastPass notes.
Victims landing on the attacker-controlled download page would find an archive containing a fake installer, a malicious file, and irrelevant data. The installer, a modified version of Microsoft’s debugging tool, executed a DLL packed with the attacker’s code.
Rapuncel Malware Functionality
Once deployed, the Rapuncel malware seeks to gain system-level privileges through Windows features, installing a kernel driver disguised as an NVIDIA graphics component. This driver is tasked with terminating 145 antivirus and endpoint security applications. Although the driver includes code to conceal itself and inject into active processes, the observed version lacked the configuration to activate these features.
With security defenses disabled, the malware proceeds to harvest stored passwords from 25 browsers, cryptocurrency data from 30 wallet apps, and tokens from Discord, Steam, and Telegram, among others. It also captures screenshots and compiles a comprehensive system profile, LastPass explains.
Connections to Other Threats
In collaboration with Delphos, LastPass’s investigation linked the campaign to Cruciferra, a crypter service detailed by Proofpoint. The malicious DLL involved in the attack was likely crafted using Cruciferra’s PUROSANGUE package, previously utilized for creating DLLs with code to disable EDR/AV systems.
The campaign shares similarities with BoryptGrab, an information stealer deployed through approximately 100 GitHub repositories earlier this year. Delphos’s analysis of the Rapuncel payload against BoryptGrab samples showed significant behavioral and artifact overlap, suggesting that Rapuncel is either a variant or a related build of BoryptGrab.
