Cybercriminals Launch Malware Campaign Impersonating LastPass and Software Firms
AI-generated from multiple sources. Verify before acting on this reporting.
SAN FRANCISCO — A sophisticated malware campaign targeting users of popular software has emerged, utilizing search engine optimization tactics to distribute a new information-stealing trojan under the guise of legitimate applications. LastPass and cybersecurity firm Delphos Labs identified the operation on Thursday, revealing that attackers are creating fraudulent GitHub repositories designed to mimic official pages for well-known technology companies.
The campaign centers on a previously undocumented malware strain dubbed Rapuncel. The malicious code is engineered to harvest a wide array of sensitive data, including user credentials, cryptocurrency wallet information, active session tokens, and system details. Additionally, the trojan scans local documents for specific keywords associated with sensitive business or personal data before exfiltrating them.
To ensure successful delivery, the actors have optimized their fake repositories for search engines, ensuring they appear prominently in results when users search for legitimate software updates or tools. By impersonating trusted brands such as LastPass, the attackers exploit user trust to encourage downloads of what appears to be authentic software.
Compounding the threat is the inclusion of a custom kernel driver within the payload. This component is specifically designed to disable Endpoint Detection and Response (EDR) systems, effectively neutralizing security software that might otherwise detect or block the infection. By killing these defenses at the operating system level, Rapuncel gains deep access to the compromised machine, allowing it to operate undetected for extended periods.
The campaign represents a significant evolution in social engineering tactics, moving beyond simple phishing emails to more persistent infrastructure-based attacks. The use of GitHub, a platform widely trusted by developers and IT professionals, adds a layer of legitimacy that makes the malicious repositories difficult to distinguish from genuine projects at a glance.
Security researchers note that the sophistication of the EDR-killing mechanism suggests the actors possess advanced capabilities in kernel-level programming. The ability to bypass modern security controls indicates a high level of technical proficiency among the group behind the attack.
As of Thursday afternoon, LastPass and Delphos Labs have issued alerts regarding the fraudulent repositories. Users are advised to verify software sources directly through official vendor channels rather than relying on search engine results or third-party code hosting sites. The full scope of the campaign remains unclear, with investigators working to determine how many systems may already be compromised.
Questions remain regarding the identity of the threat actors and whether this operation is linked to known criminal syndicates. Furthermore, it is unknown if other software brands beyond LastPass are currently being impersonated in similar fashion. The rapid deployment of SEO-optimized malware suggests the campaign may expand quickly to target additional high-profile technology firms.