AI Weekly Malaysia

Back to items Summaries

Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

ID
26956
Status
summarized
Published
22 Sep 2026, 1:31 AM
Fetched
22 Sep 2026, 3:24 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/fake-lastpass-authenticator-installer.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
5.5
Created
22 Sep 2026, 3:28 AM
Tags
Audience
developerssaas_founders

What happened

A fake LastPass Authenticator installer hosted on a GitHub page (github.com/LastPass-Authenticator) that ranks in search results delivers a 148MB ZIP containing a malicious DLL that side-loads via a renamed Microsoft debugging tool (vsdbg.exe). The payload installs a Microsoft-signed kernel driver (Alinubx.sys, signed March 2023) that terminates 145 named antivirus and EDR processes from kernel space, below where security tools can detect or block it. The driver had zero VirusTotal detections as of August and was not on Microsoft's blocked driver list.

Why it matters

If you or your team download developer or security tools from GitHub rather than official sources, this is a concrete example of a convincing impersonation page ranking in search results and bypassing every major AV/EDR product. The practical action: treat GitHub org/page names as unverified—verify downloads against vendor domains and app stores, and don't assume VirusTotal clean means safe, especially for large archives that exceed scanner size limits.

Discussion angle

How do you vet GitHub-hosted tool downloads when VirusTotal and Microsoft's own driver signing program both fail to catch active malware—what's a practical verification workflow for a small team?

Top