Fake LastPass Authenticator installs Microsoft-signed driver that kills 145 security tools
A fake LastPass Authenticator installer spread via GitHub escalates to SYSTEM and installs a Microsoft-signed kernel driver, Alinubx.sys, that terminates 145 antivirus and EDR processes before running a credential stealer against browsers, crypto wallets and Windows Credential Manager. The driver is a renamed copy of CcProtect.sys from CnCrypt; in August it scored zero detections on VirusTotal and it remains absent from Microsoft's vulnerable driver blocklist. LastPass said none of its systems or customer vaults were affected.
- Alinubx.sys kills 145 antivirus and EDR processes from kernel mode
- In August the driver had zero VirusTotal detections and was not on Microsoft's blocklist
- Stealer targets passwords from 20+ browsers, crypto wallets and Discord, Steam, Telegram sessions
- After reboot the driver re-kills security tools and re-runs the stealer
Read next
Security