Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer

Summary

A new malware campaign is using SEO-optimized GitHub repositories to impersonate legitimate software companies and distribute an unknown information stealer dubbed Rapuncel. This infostealer is designed to steal credentials and sensitive data from compromised systems.

IFF Assessment

FOE

The discovery of a new information stealer and its distribution method represents a direct threat to users and organizations, as it aims to steal sensitive data.

Defender Context

This campaign highlights the ongoing threat of impersonation attacks leveraging social engineering and compromised platforms like GitHub. Defenders should be vigilant about unexpected software downloads, verify the authenticity of repositories, and ensure robust endpoint detection and response (EDR) solutions are in place to identify and block new infostealers.

Read Full Story →