Rapuncel: Fake GitHub Repositories Disable EDR with a Signed Kernel Driver
1. Basic Information Original Title: Threat Intel | One Kit, Forty Companies: How a Malware-as-a-Service Platform Used GitHub as a Distribution Network for its Campaign Source: LastPass TIME / Delphos Labs Published Date: 2026-09-17 Updated Date: None Severity: High Basis for Severity: An active distribution infrastructure impersonating over 40 companies uses a kernel driver with a Microsoft…
This attack employs a signed kernel driver to disable EDR solutions by terminating processes associated with 145 built-in antivirus and EDR applications. The malware is distributed via high-ranking fake GitHub repositories using DLL side-loading and SSL-loaded ZIP files. Once installed, the malicious code steals sensitive data from browsers and cryptocurrency wallets, then transmits it to a command and control server.
Persistence is maintained through a Windows service, ensuring the attacker maintains control even after a system reboot.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.