chiprook
← Security
SecuritySeptember 22, 2026, 21:06

Fake LastPass Authenticator installs Microsoft-signed driver that kills 145 security tools

A fake LastPass Authenticator installer spread via GitHub escalates to SYSTEM and installs a Microsoft-signed kernel driver, Alinubx.sys, that terminates 145 antivirus and EDR processes before running a credential stealer against browsers, crypto wallets and Windows Credential Manager. The driver is a renamed copy of CcProtect.sys from CnCrypt; in August it scored zero detections on VirusTotal and it remains absent from Microsoft's vulnerable driver blocklist. LastPass said none of its systems or customer vaults were affected.

Fake LastPass Authenticator installs Microsoft-signed driver that kills 145 security tools
#LastPass#Microsoft#GitHub#Windows
Read next
Security

Hacktron used zero-day to reach OpenAI's GitHub, sparking disclosure debate

Security

NCSC: agentic AI cyber defense faces organizational, not technical, barriers

Security

Palo Alto Networks launches always-on AI security testing on Claude Mythos and GPT-5.6-Cyber

Security

Google Prompts Users to Record Face Video for Account Recovery