Ask Runable forDesign-Driven General AI AgentTry Runable For Free
Runable
Back to Blog
Technology6 min read

This fake LastPass Authenticator app will just shut off your antivirus and leave you open to attack | TechRadar

Researchers found a never-before-seen malware targeting LastPass users Discover insights about this fake lastpass authenticator app will just shut off your anti

TechnologyInnovationBest PracticesGuideTutorial
This fake LastPass Authenticator app will just shut off your antivirus and leave you open to attack | TechRadar
Listen to Article
0:00
0:00
0:00

This fake Last Pass Authenticator app will just shut off your antivirus and leave you open to attack | Tech Radar

Overview

News, deals, reviews, guides and more on the newest computing gadgets

Start exploring exclusive deals, expert advice and more

Details

Unlock and manage exclusive Techradar member rewards.

Unlock instant access to exclusive member features.

Get full access to premium articles, exclusive features and a growing list of member rewards.

This fake Last Pass Authenticator app will just shut off your antivirus and leave you open to attack

Researchers found a never-before-seen malware targeting Last Pass users

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Attackers spoofed Last Pass Authenticator via SEO‑poisoned Git Hub pages, delivering malicious ZIP files

Malware Rapuncel uses DLL sideloading, kills 145 AV products, and steals passwords, wallets, and tokens

Campaign ongoing for months; Last Pass vaults unaffected, but users urged to download only from trusted sources

Be careful when downloading the Last Pass Authenticator app - there are impostors out there that can disable your antivirus and wreak havoc on your computer.

Last Pass recently discovered an elaborate scheme to get people infected with malware - a spoofed website, SEO poisoning, DLL sideloading, and a malware loader delivering never-before-seen payload that can kill endpoint protection and antivirus solutions.

According to the password manager, users searching for "Last Pass Authenticator download" or similar keywords will get a Git Hub page rather high on the search engine results pages. At a glance, the page looks almost identical to the authentic Last Pass offering - however, it redirects users to a separate one, hosted on attacker-controlled infrastructure and delivering a large . ZIP file with multiple files.

Among the files are two worth paying attention to: vsdbg.exe, and vsdbg.dll. The . EXE one is renamed to look like a Last Pass installer, but it’s in fact a legitimate Microsoft debugging tool. This tool is used to run the malware - the vsdbg.dll file. This is a method called “dll sideloading” where the legitimate program will look for a DLL file in the same folder it’s located, rather than the wider device library. Since the DLL is delivered together with the executable, it is the first one to be run, despite the fact that it’s malicious.

Last Pass shared the malware with security researchers Delphos for analysis, and they’ve named it Rapuncel. No AV engines have been able to spot it, when it was first analyzed.

New phishing campaign hits Last Pass, Bitwarden users

Hundreds of Git Hub repos found posing as real software to push malware

Nord VPN warns of fake Ryanair, Emirates, Qatar Airways websites used to spread malware

Once Rapuncel runs, it does a number of things. First, it gains admin-level access to run as SYSTEM, and then installs a kernel driver. The driver, disguised as an NVIDIA graphics component, comes with a hardcoded list of 145 antivirus and endpoint security products, and if any of them are found on the device, they are instantly terminated.

Once all of this is harvested, the information is compressed into a . ZIP archive and uploaded to a server under the attackers’ control. To add insult to injury, the kernel driver was given code to intercept all web traffic, allowing the attackers to inject ads, or modify search results, at a whim.

Rapuncel comes with a persistence mechanism, as well, to make sure it continues operating even if the victim spots it. Spotting it should not be too difficult, though - if no antivirus programs are allowed to run on a computer, something is definitely not working properly.

Still, the malware installs itself as a Windows service that starts automatically at boot, and then loops continuously, checking for security products and killing them as soon as they’re activated. “The machine may remain fully under the attacker's control until the kernel driver is physically removed,” the researchers explained. “This process requires booting the computer into Safe Mode or using an external recovery tool, because normal Windows tools cannot safely remove software operating at that level while the system is running.”

Some Mac users think they're installing Open AI Codex, but it's actually a malware that can steal passwords in seconds

Experts warn this fake Claude install guide can be used to empty crypto wallets

A malware installer posing as a legitimate download service is infecting brands across almost every industry — Microsoft Edge, Razer, Kaspersky and more actively imitated

Last Pass and Delphos believe the campaign has been active for months, and that it will continue to operate despite disruption efforts:

“The Last Pass lure was a single recent frame in a campaign that has been running for months and shows every sign of continuing after its current infrastructure is burned,” the researchers said. They stressed that this is “opportunistic brand impersonation” and that Last Pass systems and customer vaults have not been compromised or involved in any way.

Last Pass said it was one of 40 companies spoofed in this campaign and has urged users to only download apps from reputable, vetted sources.

➡️ Read our full guide to the best antivirus

  1. Best overall: Bitdefender Total Security
  2. Best for families: Norton 360 with Life Lock
  3. Best for mobile: Mc Afee Mobile Security

Follow Tech Radar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, Io T, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Sonos Ace Ultra review: more musical, more feature-rich, much improved headphones

Sonos Beam Ultra review: one of the best compact Dolby Atmos soundbars around

I found out how easy it is to make polished PDFs with seriously limited design skills, using Adobe Acrobat’s new Stylize and Generate Report features

The Blame is on ITVX now — here's what the cast think you should stream next

Meta Muse already has a majorly worrying zero-day security issue

Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.

© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.

Key Takeaways

  • News, deals, reviews, guides and more on the newest computing gadgets
  • Start exploring exclusive deals, expert advice and more
  • Unlock and manage exclusive Techradar member rewards
  • Unlock instant access to exclusive member features
  • Get full access to premium articles, exclusive features and a growing list of member rewards

Cut Costs with Runable

Cost savings are based on average monthly price per user for each app.

Which apps do you use?

Apps to replace

ChatGPTChatGPT
$20 / month
LovableLovable
$25 / month
Gamma AIGamma AI
$25 / month
HiggsFieldHiggsField
$49 / month
Leonardo AILeonardo AI
$12 / month
TOTAL$131 / month

Runable price = $9 / month

Saves $122 / month

Runable can save upto $1464 per year compared to the non-enterprise price of your apps.