Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer

Refract AI Intelligence Digest

BLUF

Malicious software installers are bypassing endpoint defenses to steal credentials at scale.

NEWS

Attackers impersonating at least 40 companies distribute malicious installers containing a kernel-level EDR killer. This malware disables 145 security products before deploying the 'Rapuncel' stealer to harvest credentials.

Why I Care

This campaign neutralizes endpoint detection and response tools, leaving organizations vulnerable to credential theft and lateral movement. It affects any user or enterprise relying on third-party software updates.

Next Steps

IT security teams should verify software hashes against official vendors immediately and block known malicious domains. End users must avoid downloading installers from unofficial sources starting today.

The attackers impersonate at least 40 companies and disable 145 security products to deploy infostealer malware. The post Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer appeared first on SecurityWeek.
Back to Blog Listing

Source: Security Week ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.