Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer
Summary
Attackers are distributing fake LastPass installers that deliver kernel-level EDR killer malware and the 'Rapuncel' infostealer. These malicious installers impersonate over 40 companies and disable approximately 145 security products to deploy the malware.
IFF Assessment
FOE
The discovery of new malware capable of disabling security products and stealing information represents a direct threat to defenders.
Defender Context
This campaign highlights the ongoing threat of sophisticated social engineering tactics combined with advanced malware capable of evading security controls. Defenders should remain vigilant against fake installers and ensure endpoint detection and response (EDR) solutions are up-to-date and properly configured to resist kernel-level tampering.