CyberSecurity News
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
AI summary
Researchers at LastPass and Delphos Labs discovered a fake LastPass Authenticator installer on GitHub that installs a malicious Windows kernel driver. This driver is signed by Microsoft's hardware-compatibility program, which allows it to evade detection. The driver shuts down antivirus and other security software, enabling a password stealer to run undetected. When tested, the driver had zero detections on VirusTotal, indicating its ability to bypass security measures. The installer was found to be capable of disabling security software, allowing the password stealer to operate without interference.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

