Urgent.News

What's breaking now, across thousands of outlets.

Tech

This fake LastPass Authenticator app will just shut off your antivirus and leave you open to attack

Researchers found a never-before-seen malware targeting LastPass users and stealing their secrets.

This fake LastPass Authenticator app will just shut off your antivirus and leave you open to attack

Attackers have been using a fake LastPass Authenticator app to disable antivirus software and put users at risk. The scam involves SEO poisoned GitHub pages that redirect users to a malicious ZIP file. Inside the ZIP are files like vsdbg.exe, which acts as a legitimate Microsoft debugging tool and a malicious DLL called vsdbg.dll.

When run, the DLL sideloads the malware, which gains administrative access, installs a kernel driver disguised as an NVIDIA graphics component, and terminates 145 antivirus programs. The malware then steals passwords and tokens from various applications like browsers, wallets, Discord, Steam, Telegram, Windows credentials, and more.

It also intercepts web traffic, stealing data and injecting ads. The malware can persist on the infected system, staying hidden until the kernel driver is physically removed. LastPass and security researchers Delphos discovered this scheme and warn users to only download apps from trusted sources.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techradar.com →

More in Tech

More from Tuesday 22 September →