Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
- ID
- 26956
- Status
- summarized
- Published
- 22 Sep 2026, 1:31 AM
- Fetched
- 22 Sep 2026, 3:24 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/fake-lastpass-authenticator-installer.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 5.5
- Created
- 22 Sep 2026, 3:28 AM
- Tags
- Audience
- developerssaas_founders
What happened
A fake LastPass Authenticator installer hosted on a GitHub page (github.com/LastPass-Authenticator) that ranks in search results delivers a 148MB ZIP containing a malicious DLL that side-loads via a renamed Microsoft debugging tool (vsdbg.exe). The payload installs a Microsoft-signed kernel driver (Alinubx.sys, signed March 2023) that terminates 145 named antivirus and EDR processes from kernel space, below where security tools can detect or block it. The driver had zero VirusTotal detections as of August and was not on Microsoft's blocked driver list.
Why it matters
If you or your team download developer or security tools from GitHub rather than official sources, this is a concrete example of a convincing impersonation page ranking in search results and bypassing every major AV/EDR product. The practical action: treat GitHub org/page names as unverified—verify downloads against vendor domains and app stores, and don't assume VirusTotal clean means safe, especially for large archives that exceed scanner size limits.
Discussion angle
How do you vet GitHub-hosted tool downloads when VirusTotal and Microsoft's own driver signing program both fail to catch active malware—what's a practical verification workflow for a small team?