Rapuncel Infostealer Disabled 145 Security Tools Before Stealing Credentials
The Rapuncel Infostealer campaign stole browser passwords and crypto wallet data from Windows users after disabling 145 antivirus and EDR tools via a Microsoft-signed kernel driver. The driver scored 0/72 on VirusTotal after attackers renamed a Chinese driver from the LOLDrivers list, creating a new hash unknown to Microsoft and VirusTotal blocklists.
- Rapuncel disabled 145 antivirus and EDR tools before stealing data
- Used a Microsoft-signed kernel driver
- Driver scored 0/72 on VirusTotal due to a new hash
- Attackers renamed a Chinese driver from the LOLDrivers list
Read next
Security