A fake LastPass Authenticator distributed through GitHub has exposed a wider impersonation campaign delivering the Rapuncel information stealer, according to LastPass. The attackers impersonated at least 40 organisations and used search-engine optimisation to place a fraudulent GitHub download page among results for the legitimate application. They also offered a fake macOS LastPass application.
A routing chain spanning several GitHub pages and a Cloudflare-fronted server redirected victims to a changing final destination. The server was still active and serving JavaScript redirects on 10 September, although its content had changed between 27 August and 10 September. LastPass said no internal LastPass systems were compromised; the fake branding was opportunistic.
Victims ultimately received an archive containing a fake installer, a malicious file and junk. The installer, a renamed version of Microsoft’s debugging tool, loaded a companion DLL containing the attackers’ code. Rapuncel sought System privileges through built-in Windows features and installed a kernel driver disguised as an NVIDIA graphics component. The driver was designed to terminate 145 antivirus and endpoint security products.
LastPass said the observed sample did not have the required configuration to activate its code for hiding and process injection. The malware nevertheless installed as an automatically starting Windows service, repeatedly checked for security products and reran the stealer.
It targeted saved passwords from 25 browsers, cryptocurrency files from 30 wallet applications, Discord, Steam and Telegram data, the Windows credential store, and documents containing credential or wallet-related keywords; it also captured screenshots and system details.
The investigation, conducted with Delphos, linked the DLL to the Cruciferra crypter service and found strong behavioural and artefact-level similarities with BoryptGrab. Delphos assessed Rapuncel as a related variant or sibling build, rather than an identical sample.