Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
AI-summarised brief · reviewed before publication
A counterfeit LastPass Authenticator installer on GitHub deploys a Windows kernel driver that disables antivirus and EDR software before extracting passwords and cryptocurrency wallet data. Researchers from LastPass and Delphos Labs discovered the malicious driver, named Alinubx.sys, was signed by Microsoft’s hardware‑compatibility program, bypassing detection and blocklists. The driver uses DLL side‑loading and privilege escalation to reach SYSTEM, terminating 145 security processes. The stealer harvested credentials from browsers, Discord, Steam, Telegram, and Windows Credential Manager, sending them to an attacker server.
💡 Why It Matters
- · The attack demonstrates how legitimate driver signing can be weaponized, exposing a critical blind spot in Windows security that bypasses user‑mode defenses and undermines trust in Microsoft’s attestation process.