Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
Summary
A fake LastPass Authenticator installer distributed on GitHub has been found to install a Windows kernel driver. This driver is signed by Microsoft and is capable of disabling antivirus and endpoint detection and response (EDR) software before deploying a password stealer.
IFF Assessment
FOE
This article details a malicious installer that bypasses security defenses, representing a significant threat to defenders.
Defender Context
Defenders should be aware of sophisticated attack techniques that leverage trusted elements, like Microsoft-signed drivers, to circumvent security measures. Users must exercise extreme caution when downloading software, especially from less reputable sources like GitHub, and verify the authenticity of installers.