A fake LastPass Authenticator installer available on GitHub has been found to install a Windows kernel driver that disables antivirus and other security software, allowing a password stealer to operate undetected. This alarming discovery was reported by researchers at LastPass and Delphos Labs on September 17.
The malicious driver, which is signed through Microsoft’s hardware compatibility program, managed to evade detection on VirusTotal and was not listed on Microsoft’s blocked drivers list. LastPass confirmed that its systems and customer vaults were not compromised, indicating that the attackers merely exploited the LastPass name.
The attack begins with a fraudulent GitHub page that appears legitimate and ranks highly in search results for terms like “LastPass Authenticator download.” When users click the download button, they are redirected through several GitHub pages to an attacker-controlled server that serves a large ZIP file. Users are advised to download the LastPass Authenticator only from lastpass.com or official app stores.
Mechanism of the Attack
Inside the ZIP file, a legitimate Microsoft debugging tool, vsdbg.exe, is included alongside a malicious file named vsdbg.dll. When the installer is executed, Windows loads the attacker’s DLL using a technique known as DLL side-loading. The loader attempts to gain administrator rights and installs the kernel driver as a service.
This kernel driver, identified as Alinubx.sys, operates below the level of antivirus and endpoint detection tools, allowing it to terminate 145 security processes without detection. This method, known as “bring your own vulnerable driver” (BYOVD), exploits the trust placed in signed drivers. The driver was signed in March 2023, long before this attack.
Consequences of the Attack
Once the security software is disabled, the password stealer collects sensitive information, including saved passwords from over two dozen browsers, cryptocurrency wallet files, and login sessions for platforms like Discord, Steam, and Telegram. The data is then compressed into a ZIP file and sent to an attacker-controlled server.
Researchers noted that the driver is a renamed version of CcProtect.sys, a known process killer, which had previously been flagged by antivirus engines. The renaming allowed it to bypass detection, as the original driver was not on Microsoft’s vulnerable driver blocklist.
Delphos Labs reported the driver to Microsoft, but the company stated that the behavior did not meet its criteria for a security vulnerability, as the driver is not a Microsoft component.
Recommendations for Affected Users
Users who may have downloaded the fake installer should consider all passwords saved in their browsers as compromised. It is recommended to change these passwords from a secure device and to monitor account activity for any unauthorized actions. The driver remains active on infected machines, re-enabling the password stealer on each reboot.
For further details, refer to the full report by The Hacker News.
Follow Cyber Warriors Middle East for further global cybersecurity developments.


