Fake LastPass Authenticator Installs a Microsoft-Signed Driver That Kills 145 Security Tools
TL;DR what: A fake LastPass Authenticator installer on GitHub side-loads a malicious DLL, escalates to SYSTEM, and installs a Microsoft-signed kernel driver named Alinubx.sys that terminates 145 antivirus and EDR processes before running a credential stealer. A fake LastPass Authenticator installer distributed through GitHub installs a Microsoft-signed Windows kernel driver that terminates 145…
A malicious installer for a fake LastPass Authenticator on GitHub installs a signed Windows kernel driver named Alinubx.sys. The driver terminates 145 antivirus and EDR processes. After running a credential stealer, the threat can access saved passwords, cryptocurrency wallet files, Discord and Steam sessions, and files with specific keywords in their names. This attack impacts user credentials across various platforms, requiring users to rotate their passwords from a separate clean device.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.