Fake LastPass Tool Uses Microsoft Driver to Kill Antivirus — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Fake LastPass Authenticator installer distributed via GitHub installs a Windows kernel driver that disables antivirus and EDR software, enabling subsequent malware execution
- Microsoft-signed driver is leveraged by the malware to gain trusted status and terminate security processes on infected systems
- LastPass and Delphos Labs researchers identified the attack chain and issued warnings on September 17 after analyzing the malicious package
- Password stealer runs only after security tools are disabled, increasing stealth and persistence of the threat
Why it matters: This abuse of a Microsoft-signed driver undermines trust in code-signing as a security control, putting organizations relying on EDR at higher risk of undetected breaches. The tactic raises the bar for attackers to bypass defenses using legitimate infrastructure.
Ask SkimNews




