This fake LastPass Authenticator app will just shut off your antivirus and leave you open to attack
Researchers found a never-before-seen malware targeting LastPass users and stealing their secrets.
Attackers have been using a fake LastPass Authenticator app to disable antivirus software and put users at risk. The scam involves SEO poisoned GitHub pages that redirect users to a malicious ZIP file. Inside the ZIP are files like vsdbg.exe, which acts as a legitimate Microsoft debugging tool and a malicious DLL called vsdbg.dll.
When run, the DLL sideloads the malware, which gains administrative access, installs a kernel driver disguised as an NVIDIA graphics component, and terminates 145 antivirus programs. The malware then steals passwords and tokens from various applications like browsers, wallets, Discord, Steam, Telegram, Windows credentials, and more.
It also intercepts web traffic, stealing data and injecting ads. The malware can persist on the infected system, staying hidden until the kernel driver is physically removed. LastPass and security researchers Delphos discovered this scheme and warn users to only download apps from trusted sources.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.