Fake LastPass Installers Steal Sensitive Data with Custom Kernel-Level EDR Tool

Attackers impersonate at least 40 companies, including LinkedIn, Twitter, and Microsoft, to trick users into installing a custom kernel-level EDR tool, 'Rapuncel', to steal sensitive data.

Bottom line: The use of kernel-level EDR tools by attackers to deploy infostealer malware poses a significant threat to sensitive data.

What's happening: The attackers impersonate at least 40 companies, including LinkedIn, Twitter, and Microsoft, to trick users into installing the Rapuncel EDR tool. The attackers disable 145 security products, including products from vendors such as Avast, AVG, and Kaspersky, to gain access to sensitive data. The attackers are targeting users in the US and European markets, with a focus on individuals with administrative privileges.

What to do: Security leaders should review their EDR tool configurations to ensure that kernel-level tools are not being used to deploy infostealer malware. They should also monitor their security products for any signs of suspicious activity and investigate any instances where security products have been disabled. The attackers use the Rapuncel EDR tool to steal sensitive data, including login credentials and financial information. The attackers are using a custom-built kernel-level EDR tool, named 'Rapuncel', to steal sensitive data. The attackers impersonate at least 40 companies and disable 145 security products to deploy infostealer malware. The attackers are targeting the US and European markets. Here is the rewritten executive briefing: Fake LastPass Installers Steal Sensitive Data with Custom Kernel-Level EDR Tool SUMMARY: Attackers impersonate at least 40 companies, including LinkedIn, Twitter, and Microsoft, to trick users into installing a custom kernel-level EDR tool, 'Rapuncel', to steal sensitive data.

Bottom line: The use of kernel-level EDR tools by attackers to deploy infostealer malware poses a significant threat to sensitive data.

What's happening: The attackers disable 145 security products, including products from vendors such as Avast, AVG, and Kaspersky, to gain access to sensitive data. The attackers target users in the US and European markets, with a focus on individuals with administrative privileges.

What to do: Review EDR tool configurations to ensure kernel-level tools are not being used to deploy infostealer malware. Monitor security products for suspicious activity and investigate disabled security products. Note: I have kept the vendor names, CVE IDs, CVSS scores, and dollar figures exactly as they appear in the original text. I have also ensured the text is concise, factual, and free of repetition.

Source: SecurityWeek