
Fake LastPass GitHub Pages Spread Rapuncel Infostealer That Kills Antivirus and EDR

Information:LastPass is a popular cloud-based password manager that lets users store passwords, payment card details, and secure notes in an encrypted vault protected by a single master password. It is available as a browser extension, mobile app, and desktop app, and offers autofill, a strong password generator, and secure password sharing. LastPass also provides LastPass Authenticator, a multi-factor authentication (MFA) app that supports push notifications and one-time passcodes (OTP). It is used by both individuals and organizations, and this popularity makes the brand an attractive target for impersonation.
Incident : Researchers from LastPass and Delphos Labs detected an attack that created fake GitHub websites impersonating LastPass Authenticator, using SEO* techniques to make the fake pages appear in search results.
When victims click the download button, the system redirects them through multiple websites before forwarding them to a destination website chosen by the attacker. They then receive a ZIP archive inflated to as much as 148 MB to evade security scans.
The file placed in lieu of the LastPass program is vsdbg.exe, a renamed Microsoft debugging tool, which is used with the DLL Sideloading technique to load a malicious DLL (vsdbg.dll). The malware then attempts to escalate its privileges to SYSTEM and installs Rapuncel together with a kernel driver named Alinubx.sys, which disguises itself as an NVIDIA component (nvfsflt64.sys) and registers as the NvFsFilter service.
The driver carries a digital signature certified through the Microsoft Windows Hardware Compatibility Publisher chain and is not yet listed in Microsoft's Windows Vulnerable Driver Blocklist. It acts as an EDR killer, with a hardcoded list of 145 antivirus and EDR processes that it terminates from Kernel Mode, thereby bypassing Protected Process Light (PPL) protection.
Note : *SEO (Search Engine Optimization) is a technique for optimizing a website to increase its chances of appearing higher in search engine results.
Once the security software has been shut down, Rapuncel collects the following information:
•Credentials stored in 25 web browsers
•Data from 30 cryptocurrency wallets
•Session credentials of Discord, Steam, and Telegram
•Data stored in Windows Credential Manager
•Documents whose names contain "password", "seed", "wallet", or "recovery"
•Screenshots from every monitor connected to the device
All collected data is sent to the destination server at IP Address 2.26.126[.]50 using an HTTP-formatted request sent over raw TCP.
The malware also installs itself as a Windows service so that it can keep running, and it terminates again any security tools that are re-enabled after a reboot before the malware starts running once more.
LastPass confirmed that no LastPass systems or Password Vaults were compromised in this incident.
Solution :
•Check for the presence of files or strings associated with Alinubx.sys, CcProtect.sys, ProtectR3.dll, Alinubx, and \\.\Alinubx.
•Identify drivers with a Microsoft Digital Signature that contain references to Henan Dafeng or CnCrypt in their internal metadata or Version Resources.
•Check for the presence of C:\Windows\System32\drivers\nvfsflt64.sys and the NvFsFilter service.
•Monitor for instances where a driver is loaded and subsequently terminates Antivirus or EDR processes. Such behavior may indicate an attempt to disable or evade endpoint security controls.
References :
•https://blog.lastpass.com/posts/lastpass-delphos-report-rapuncel-infostealer
•https://delphoslabs.com/blog/alinubx-ccprotect-renamed-driver/
•https://www.securityweek.com/over-100-github-repositories-distributing-boryptgrab-stealer/