This fake LastPass Authenticator app will just shut off your antivirus and leave you open to attack

In a troubling development for cybersecurity, LastPass has uncovered a sophisticated scheme targeting users of its Authenticator app. Attackers have employed a combination of SEO poisoning and deceptive GitHub pages to distribute malicious ZIP files masquerading as legitimate software. This tactic has raised significant concerns, particularly as users searching for “LastPass Authenticator download” may inadvertently stumble upon these counterfeit pages, which closely resemble the authentic LastPass site.

Upon accessing these fraudulent pages, users are redirected to a malicious server that delivers a ZIP file containing several files, including two particularly noteworthy ones: vsdbg.exe and vsdbg.dll. The executable file is cleverly disguised as a LastPass installer, but it is, in fact, a legitimate Microsoft debugging tool. This tool is exploited to execute the accompanying DLL file, which is malicious in nature. This technique, known as DLL sideloading, allows the malware to run before any legitimate security measures can intervene.

Rapuncel

Security researchers from Delphos have named the malware Rapuncel, and its capabilities are alarming. Initial analyses revealed that no antivirus engines could detect it. The malware is designed to target a hardcoded list of 145 antivirus and endpoint security products, disabling them immediately upon detection. Once these defenses are neutralized, Rapuncel proceeds to harvest sensitive information, including saved passwords from over 25 web browsers, cryptocurrency wallet files from more than 30 applications, and various session tokens from platforms such as Discord and Steam.

In addition to stealing credentials, Rapuncel captures screenshots of all connected monitors and compiles a detailed profile of the infected system. This stolen data is then compressed into a ZIP archive and uploaded to a server controlled by the attackers. To further complicate matters, the malware includes a kernel driver capable of intercepting web traffic, enabling attackers to inject advertisements or manipulate search results at will.

Active for months

This campaign has been ongoing for several months, and while LastPass vaults remain unaffected, users are strongly advised to download applications only from trusted sources. Rapuncel is designed to establish persistence on infected machines, ensuring it continues to operate even if detected. It installs itself as a Windows service that automatically starts with the system, continuously checking for and terminating any activated security products. Researchers have noted that a machine may remain under the attacker’s control until the kernel driver is physically removed, a process that requires booting into Safe Mode or utilizing external recovery tools, as standard Windows utilities cannot safely eliminate software operating at that level.

Tech Optimizer
This fake LastPass Authenticator app will just shut off your antivirus and leave you open to attack