GitHub: fake LastPass Authenticator installer steals passwords

Author: Published 6 min de lectura 13 reading

The images in this article were generated with artificial intelligence. How we publish

LastPass and Delphos Labs researchers have documented a suplanting campaign that offered a false installer of the "LastPass Authenticator" in GitHub. If a victim downloaded and executed the package, a technical abuse chain was activated that finished security processes from the Windows core (kernel) and allowed the execution of apassword stealerwhich exfiltered passwords, sessions and files of cryptomoneda coins. The decoy was a page of GitHub that appeared to be the legitimate product; the real installer of LastPass Authenticator comes only from lastpass.com and official stores. (confirmed by LastPass and Delphos Labs).

Technically, the observed sample delivered a large ZIP containing a legitimate renamed copy of a Microsoft debugger (vsdbg.exe) along with a malicious DLL (vsdbg.dll). When running the debugger, Windows loads the DLs from the same folder: that abuse is known as DLL side-loading and is the mechanism that triggers the attacker's charger. The loader tries to obtain administrator privileges on three different routes and manages to rise to SYSTEM; with these privileges installs a kernel driver (driver) as a service. (confirmed by the investigation).

GitHub: fake LastPass Authenticator installer steals passwords
Image generated with IA.

The driver, renamed in the campaign as Alinubx.sys, is not a new development: it derives from CcProtect.sys, a controller of a Chinese encryption product (CnCrypt) that already circulates with public evidence of abuse. The file was signed through Microsoft's hardware compatibility publishing chain with March 2023 signature date. The researchers stress that Microsoft's attention proves that the binary went through a confidence process, but does not certify that the driver is safe. In addition, the driver was designed to run a list of 145 security process names and finish them from the kernel, which prevents user-level antivirus processes from detecting or blocking such deaths. (Signed).

Some observed features add effectiveness to the campaign: ZIP were huge (e.g. 148 MB) and were filled with junk files to evade scanners that apply size limits; VirusTotal recorded zero detections for the renowned driver when Delphos checked it in August; and the driver did not appear on the list of Microsoft-blocked drivers at the time of the report. Delphos notified Microsoft on August 19; Microsoft responded that the behavior did not fit its definition of vulnerability because it is not a Microsoft component and referred to the path for consideration of the blickelist. As of the September 17 joint report, Alinubx.sys was still not blocked. (confirmed facts; the Bloquelist's response and status are documented by researchers and by Microsoft).

Once the driver neutralizes the defenses, thestealer- called Rapuncel by LastPass and related to previous families distributed by false repositories in GitHub - extract passwords saved in more than two dozen browsers, wallets files, Discord / Steam / Telegram sessions, Windows Credentials Manager and any files with names such as "password," "seen" or "recovery." To skip the protection of modern versions of Chrome and Edge (the so-called application-linked encryption), the stealer injects code and requests the browser process itself to decipher the passwords. The data are packed in ZIP and exfiltered to the attacker's server. (Confirmed by telemetry and sample analysis; relationship with previous families is an evaluation of researchers).

Who does it affect and what impact does it have? Any user who downloaded and ran the malicious installer on Windows is at risk. Researchers warn that all the credentials stored on the affected equipment, as well as sensitive sessions and files, must be assumed to be stolen. The commitment is kernel-level: the driver reinstates and reapplies the "killing" of security processes in each reboot, which makes it difficult to clean by conventional means and makes the equipment a permanently compromised system until it is resolved at kernel level or the system is reinstalled. (Signed).

What is clear (facts): the decoy in GitHub, the DLL side-loading chain with vsdbg.exe / vsdbg.dll, the lifting to SYSTEM, the installation of the signed driver and the termination from security processes; the exfiltration of passwords and wallets; the notification of Delphos to Microsoft and the absence of the file in the blickelist on the date of the report. What is estimate or evaluation: the precise attribution of how many users were victims (unreported), the exact relationship between Rapuncel and other families (Delphos speaks of relationship), and the likelihood of future changes in the driver's name (high, but foresight).

Specific measures to be taken by any reader who may have downloaded something similar:

Seal the equipment immediately. Disconnect the machine from the network and turn off if possible to prevent further exfiltration. Don't reinstate credentials on that team.

Provide a clean device for account recovery. From another team that is checked as clean, change passwords from all the accounts accessed from the engaged machine (mail, banking, social networks, shops, exchanges, etc.) and revoke tokens / active sessions when the service allows. Activate / force multifactor authentication where possible.

Treat the affected equipment as compromised at the kernel level. The recommended action is a complete system reconstruction (formatting and reinstallation) or, if the platform allows, a forensic analysis of kernel with specialized personnel or services; surface cleaning from user or antivirus is not reliable because the driver kills safety again when reboot. Search for technical signals before reuse: service created called NvFsFilter, file in C:\ Windows\ System32\ drivers\ nvfsflt64.sys, device\\.\ Alinubx or signatories including Henan Dafeng Software / CnCrypt. (Detected by Delphos and shared in his report).

Revocate and regenerate keys and wallets. If there were files of purse or seeds on the computer, assume that they are committed and move funds from addresses associated with them using wallets created on hardware or secure devices, after transferring the funds to new addresses.

GitHub: fake LastPass Authenticator installer steals passwords
Image generated with IA.

Immediate good preventive practices: do not download installers from third-party repositories or search engines; always confirm the official URL of the supplier; prefer official stores and verified signatures; keep Windows and the driver block catalogue updated. Microsoft documents how the bloquelist and the driver signature works; administrators should review and implement Microsoft recommended policies to mitigate vulnerable drivers. (More technical details of driver management and response in Microsoft documentation: https: / / learn.microsoft.com / en-us / windows-hardware / drivers / kernel / blocking-vulnerable-drivers).

If you want to read the complete technical analysis and IOCs indicators, see the joint Delphos Labs report and LastPass public notes; the teams provide useful details for detection and response. (Delphos report with technical and observable breakdown: https: / / delpholabs.io / blog / lastpass-authenticator-impersonation / and historical context about using GitHub repositories as a vector: for example, analysis of malware campaigns that used false repositories recently by security firms like Trend Micro).

In short, it was not a gap in LastPass or its services, but a campaign that exploited confidence in legitimate signatures and mechanisms (Microsoft driver signature, official debugging) and known techniques (DLL side-loading and BYOVD) to leave security software unresponsive. The key to users and administrators is to act under the assumption of loss of credentials if the installer was executed, restore accounts from a clean device and treat the affected equipment as a kernel infection that requires reconstruction or expertise.

Coverage

Related

More news on the same subject.