Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fake LastPass App Distributes Rapuncel Malware

Fake LastPass App Distributes Rapuncel Malware

Posted on September 21, 2026 By CWS

A deceptive version of the LastPass Authenticator distributed via GitHub has unveiled a widespread impersonation campaign aimed at disseminating information-stealing malware, according to reports from LastPass.

Impersonation Campaign Tactics

The attackers behind this scheme have impersonated over 40 organizations to distribute a Microsoft-certified kernel driver. This driver is engineered to disable 145 security tools, paving the way for a malicious program known as Rapuncel.

First identified on August 13, the fraudulent LastPass application demonstrates strategic brand spoofing. Importantly, no internal systems of LastPass were compromised. The campaign has been active for several months, leveraging SEO techniques to ensure the attackers’ GitHub page appeared prominently in search results for the legitimate application. Another page was misleadingly offering a fake macOS version of LastPass.

Technical Details of the Attack

To divert victims, the attackers employed a concealed routing chain using multiple GitHub pages and a server masked by Cloudflare, allowing dynamic control over the final destination. As of September 10, the server was operational, with changes in content observed between August 27 and September 10, indicating ongoing management, LastPass notes.

Victims landing on the attacker-controlled download page would find an archive containing a fake installer, a malicious file, and irrelevant data. The installer, a modified version of Microsoft’s debugging tool, executed a DLL packed with the attacker’s code.

Rapuncel Malware Functionality

Once deployed, the Rapuncel malware seeks to gain system-level privileges through Windows features, installing a kernel driver disguised as an NVIDIA graphics component. This driver is tasked with terminating 145 antivirus and endpoint security applications. Although the driver includes code to conceal itself and inject into active processes, the observed version lacked the configuration to activate these features.

With security defenses disabled, the malware proceeds to harvest stored passwords from 25 browsers, cryptocurrency data from 30 wallet apps, and tokens from Discord, Steam, and Telegram, among others. It also captures screenshots and compiles a comprehensive system profile, LastPass explains.

Connections to Other Threats

In collaboration with Delphos, LastPass’s investigation linked the campaign to Cruciferra, a crypter service detailed by Proofpoint. The malicious DLL involved in the attack was likely crafted using Cruciferra’s PUROSANGUE package, previously utilized for creating DLLs with code to disable EDR/AV systems.

The campaign shares similarities with BoryptGrab, an information stealer deployed through approximately 100 GitHub repositories earlier this year. Delphos’s analysis of the Rapuncel payload against BoryptGrab samples showed significant behavioral and artifact overlap, suggesting that Rapuncel is either a variant or a related build of BoryptGrab.

Security Week News Tags:BoryptGrab, Cruciferra, cyber attack, Cybersecurity, Delphos, fake apps, GitHub, information stealer, kernel driver, LastPass, Malware, Microsoft, Nvidia, Rapuncel, security tools

Post navigation

Previous Post: PowerShell Backdoor TASK#STOMP Steals Sensitive Data
Next Post: Microsoft Entra ID to End SMS Sign-In by 2027

Related Posts

Braintrust Urges API Key Changes Following Security Breach Braintrust Urges API Key Changes Following Security Breach Security Week News
FireCompass Raises  Million for Offensive Security Platform FireCompass Raises $20 Million for Offensive Security Platform Security Week News
Check Point to Acquire AI Security Firm Lakera Check Point to Acquire AI Security Firm Lakera Security Week News
Elastic Refutes Claims of Zero-Day in EDR Product Elastic Refutes Claims of Zero-Day in EDR Product Security Week News
PwC and Google Cloud Ink 0 Million Deal to Scale AI-Powered Defense PwC and Google Cloud Ink $400 Million Deal to Scale AI-Powered Defense Security Week News
Cybersecurity Firms React to China’s Reported Software Ban Cybersecurity Firms React to China’s Reported Software Ban Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Probes Teams Calling Disruption Affecting Users
  • Cyberattacks Target Colorado Water Utilities’ OT Systems
  • Microsoft Entra ID to End SMS Sign-In by 2027
  • Fake LastPass App Distributes Rapuncel Malware
  • PowerShell Backdoor TASK#STOMP Steals Sensitive Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Probes Teams Calling Disruption Affecting Users
  • Cyberattacks Target Colorado Water Utilities’ OT Systems
  • Microsoft Entra ID to End SMS Sign-In by 2027
  • Fake LastPass App Distributes Rapuncel Malware
  • PowerShell Backdoor TASK#STOMP Steals Sensitive Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark