Microsoft-Signed Driver Used to Kill Antivirus in Fake LastPass App — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Fake LastPass Authenticator installer distributed via a spoofed GitHub page installs a malicious kernel driver that disables antivirus and endpoint detection software before running a password stealer
- Alinubx.sys driver — a renamed version of CnCrypt's CcProtect.sys — is signed through Microsoft’s Windows Hardware Compatibility Publisher chain and was not on Microsoft’s vulnerable driver blocklist as of August 20
- DLL side-loading technique uses a legitimate Microsoft debugging tool (vsdbg.exe) alongside a malicious vsdbg.dll to gain SYSTEM privileges and install the driver as a service named NvFsFilter
- Password stealer extracts saved credentials from over two dozen browsers, cryptocurrency wallets, Discord, Steam, Telegram sessions, and Windows Credential Manager, bypassing Chrome/Edge encryption by injecting into browser processes
- Delphos Labs and LastPass researchers found the driver scored zero detections on VirusTotal in August due to renaming, despite the original being flagged by 7 of 70 engines
- Microsoft declined to classify the driver’s behavior as a security vulnerability, directing researchers to a separate blocklist submission process, which Delphos used on August 19
- Attack infrastructure impersonated at least 40 brands beyond LastPass, with similar fake GitHub repositories observed since March using tools like Cruciferra crypter and stealers related to BoryptGrab
Why it matters: This attack exploits trust in Microsoft’s signing authority to disable core security defenses at the kernel level, meaning organizations can no longer assume signed drivers are safe — especially when blocklists fail to cover known-abusable drivers. The lack of hash-based blocking allows trivial evasion through renaming, undermining a key Windows 11 defense layer.
Ask SkimNews




