Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

Summary

A fake LastPass Authenticator installer distributed on GitHub has been found to install a Windows kernel driver. This driver is signed by Microsoft and is capable of disabling antivirus and endpoint detection and response (EDR) software before deploying a password stealer.

IFF Assessment

FOE

This article details a malicious installer that bypasses security defenses, representing a significant threat to defenders.

Defender Context

Defenders should be aware of sophisticated attack techniques that leverage trusted elements, like Microsoft-signed drivers, to circumvent security measures. Users must exercise extreme caution when downloading software, especially from less reputable sources like GitHub, and verify the authenticity of installers.

Read Full Story →