EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

Editorial source
Editorial OSINT source. The content is an indication to verify with independent institutional or technical sources before operational decisions.
EudorIA operational summary

What it means

Priority 85/100

Un falso installer di LastPass Authenticator, disponibile su GitHub, include un driver kernel firmato da Microsoft che disattiva antivirus e EDR. Il driver, chiamato Alinubx.sys, termina processi di sicurezza e ruba credenziali da browser e wallet. Il malware non è stato rilevato da VirusTotal e non è nel blocco driver di Microsoft. La vittima deve considerare le credenziali rubate e ripristinare le password da dispositivi separati.

Why it matters

Per le PMI italiane, il rischio è alto: il malware può rubare credenziali di accesso, wallet criptovaluta e dati sensibili. La mancanza di rilevamento da parte di antivirus e EDR rende il malware particolarmente pericoloso e difficile da rilevare.

Potential operational benefits

  • Riduzione della superficie esposta a malware non rilevati
  • Miglioramento della rilevazione e risposta agli attacchi kernel-level
  • Protezione dei dati sensibili e delle credenziali
  • Riduzione del rischio di compromissione a lungo termine
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsFirewall NGFW / IPSEDR / XDRMonitoraggio / SIEMPatch managementSegmentazione di rete
AudienceITSOCCISO
Information centre

Translation in progress

The Hacker News

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17. Microsoft's own hardware-compatibility program signs the driver, scored zero detections on VirusTotal when researchers

Source
The Hacker News
Publishing entity
The Hacker News
Entity type
editorial osint
Area
Global
Original language
en · translation in preparation
Publication
21/09/2026 19:31
MITRE ATT&CK
T1190, T1078, T1486
Open the original source