Skip to main content

Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer

0
High
Malwaremalware
Published: 09/21/2026 (09/21/2026, 15:46:58 UTC)
Source: SecurityWeek

Description

A widespread campaign impersonates LastPass and at least 40 other companies to distribute a kernel-level malware called Rapuncel via fake installers hosted on GitHub. The malware disables 145 security products by loading a malicious kernel driver and steals sensitive information including passwords, cryptocurrency wallets, and tokens from multiple applications. The campaign uses SEO manipulation and dynamic redirect chains to lure victims. Rapuncel installs as a persistent Windows service, continuously killing security tools and stealing data until the kernel driver is physically removed.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/21/2026, 16:01:49 UTC

Technical Analysis

Attackers impersonate over 40 companies, including LastPass, to distribute a fake LastPass Authenticator installer via GitHub. The installer is a renamed Microsoft debugging tool that loads a malicious DLL containing Rapuncel malware. Rapuncel installs a kernel driver masquerading as an NVIDIA graphics component designed to terminate 145 antivirus and endpoint security products. Although the driver observed lacked full activation, it hides itself and injects code into running processes. The malware escalates privileges, installs persistently as a Windows service, and continuously kills security tools. It steals saved passwords from 25 browsers, cryptocurrency wallets from 30 applications, Discord, Steam, Telegram tokens, Windows credentials, and documents with credential-related keywords. It also captures screenshots and detailed system profiles. The campaign uses SEO to rank fake GitHub pages highly and employs a Cloudflare-fronted server for dynamic redirection. The malicious DLL is linked to the Cruciferra crypter service and shows behavioral overlap with the BoryptGrab stealer family.

Potential Impact

The malware can disable a wide range of security products, allowing it to operate undetected and persistently on infected systems. It steals extensive sensitive data including passwords, cryptocurrency wallets, messaging tokens, and system information. The persistence mechanism ensures continuous data theft and control until the kernel driver is physically removed. This poses a significant risk of credential theft, financial loss, and system compromise for affected users.

Defensive Guidance

No official patch or remediation is indicated in the available information. Since the campaign relies on fake installers distributed via GitHub and SEO manipulation, users should only download software from verified official sources. Endpoint detection and response solutions should be updated to detect this threat. Removal requires physical removal of the kernel driver, indicating that standard uninstall methods may be ineffective. Monitoring for suspicious kernel drivers and unauthorized service installations is recommended. Users should be cautious of unexpected prompts to install software, especially from search results or third-party sites.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.88,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/fake-lastpass-installers-push-kernel-level-edr-killer-rapuncel-stealer/","fetched":true,"fetchedAt":"2026-09-21T16:01:39.398Z","wordCount":1199}

Threat ID: 6ab154e355bf5e2cf51e8f50

Added to database: 09/21/2026, 16:01:39 UTC

Last enriched: 09/21/2026, 16:01:49 UTC

Last updated: 09/22/2026, 00:04:24 UTC

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses