A fake LastPass Authenticator installer hosted on GitHub installs a Windows kernel driver that disables antivirus and endpoint security before a stealer runs, according to research from LastPass and Delphos Labs published on 17 September. The lure is a counterfeit GitHub page (github.com/LastPass-Authenticator) that ranks in search results for download terms and imitates a genuine product page; the real application is distributed from lastpass.com and the official app stores. Clicking through leads to an attacker server serving a padded ZIP — the samples seen were 148 MB and 127.9 MB, inflated with junk files so size-limited scanners skip them — containing a renamed copy of Microsoft's vsdbg.exe beside a malicious vsdbg.dll. Windows loads the attacker's DLL from the same folder by DLL side-loading, after which the loader makes three attempts at administrator rights, reaches SYSTEM and installs the driver as a service. The driver, named Alinubx.sys, carries a list of 145 antivirus and security process names and terminates each one from kernel level, below where those tools run. It is signed through Microsoft's Windows Hardware Compatibility Publisher chain with a March 2023 signing date, scored zero detections on VirusTotal when checked in August and was absent from Microsoft's blocked-driver list — a bring your own vulnerable driver (BYOVD) technique. With defences down, the stealer harvested saved passwords from more than two dozen browsers, cryptocurrency wallet files, Discord, Steam and Telegram sessions, Windows Credential Manager contents and files named like "password", "seed" or "recovery". LastPass says none of its systems, services or customer vaults were affected.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-09-22 |
| Source | The Hacker News |
| Reliability | Tier 2 |