Interestana
Home/News/Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Evade Security Software
The Hacker News4 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Evade Security Software

Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Evade Security Software

Security researchers from LastPass and Delphos Labs have uncovered a sophisticated attack campaign utilizing a fake installer for the LastPass Authenticator application. This malicious software, discovered on GitHub, employs a Windows kernel driver that is digitally signed by Microsoft through its Windows Hardware Compatibility Program (WHCP). The WHCP is a Microsoft initiative designed to ensure that hardware and software drivers meet certain compatibility and reliability standards, and drivers certified through this program are often trusted by the operating system and security software. The attackers have leveraged this trust by obtaining or exploiting a legitimate-looking, Microsoft-signed driver. Once the victim downloads and executes the fake installer, it proceeds to install this kernel-mode driver. The primary function of this driver is to operate at a privileged level within the Windows operating system, allowing it to systematically disable or terminate critical security processes. This includes terminating antivirus software and endpoint detection and response (EDR) solutions, which are designed to protect systems from malware and malicious activity. By neutralizing these defenses, the attackers create an environment where their subsequent malicious payload can operate undetected. Following the successful disabling of security software, the installer then deploys a password-stealing malware. This malware is designed to exfiltrate sensitive information, such as user credentials, from the compromised system, potentially leading to account takeovers and further security breaches. The researchers highlighted that at the time of their analysis on September 17, this specific malicious driver achieved zero detections on VirusTotal, a popular online service that analyzes files for malware using multiple antivirus engines. This indicates a high degree of evasion capability, making it difficult for traditional security tools to identify the threat. The attack chain begins with users being deceived into downloading the fake installer, likely from a compromised or impersonated GitHub repository, which is a platform commonly used for software development and distribution. The reliance on a Microsoft-signed driver is a significant development, as it represents an advanced technique to bypass security measures by exploiting a trusted component of the Windows ecosystem. This incident underscores the persistent challenges in cybersecurity, particularly in detecting advanced threats that leverage legitimate infrastructure and processes to achieve their objectives. It also serves as a critical reminder for users to exercise extreme caution when downloading software, even from seemingly reputable sources like GitHub, and to always verify the authenticity of applications.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next