Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer
BLUF
Malicious software installers are bypassing endpoint defenses to steal credentials at scale.
NEWS
Attackers impersonating at least 40 companies distribute malicious installers containing a kernel-level EDR killer. This malware disables 145 security products before deploying the 'Rapuncel' stealer to harvest credentials.
Why I Care
This campaign neutralizes endpoint detection and response tools, leaving organizations vulnerable to credential theft and lateral movement. It affects any user or enterprise relying on third-party software updates.
Next Steps
IT security teams should verify software hashes against official vendors immediately and block known malicious domains. End users must avoid downloading installers from unofficial sources starting today.
Source: Security Week ·