Attackers created a counterfeit LastPass repository on GitHub to distribute malware, using a Microsoft-signed driver to disable 145 antivirus and endpoint detection and response products before deploying an infostealer. The campaign highlights growing risks in software supply chains, where threat actors exploit trust in widely used platforms and security certification processes.

The attack began with a spoofed GitHub repository impersonating the official LastPass authenticator. Users who downloaded the malicious payload received software containing a kernel-mode driver. Despite being flagged by endpoint security tools, the driver carried a legitimate Microsoft signature—a certification that validates software compatibility and publisher identity but does not assess malicious intent.

Once executed with kernel-level privileges, the signed driver terminated the processes of 145 distinct security products, removing endpoint defenses across affected systems. With security monitoring neutralized, the infostealer harvested sensitive user data without detection.

Security researchers observed that the incident targets trust mechanisms rather than exploiting traditional software vulnerabilities. Microsoft's driver signing program, designed to assure users of software provenance and compatibility, became a vector for bypassing security controls. Researchers noted that a signed binary does not guarantee safe behavior, challenging a common assumption among users and administrators.

The full report is available at Security Affairs.


攻擊者在GitHub上建立了一個偽造的LastPass儲存庫以分發惡意軟件,利用微軟簽核的驅動程式,在部署信息竊取程式之前,先令145種防毒軟件及端點偵測與回應產品失效。該行動突顯了軟件供應鏈中日益增長的風險,威脅行為者利用廣泛使用的平台及安全認證流程所贏得的信任進行攻擊。

攻擊始於一個冒充官方LastPass驗證器的偽造GitHub儲存庫。下載了惡意載荷的用戶,其收到的軟件中包含一個內核模式驅動程式。儘管被端點安全工具標記,該驅動程式卻附有微軟的合法簽核——這項認證用於驗證軟件的相容性和發布者身份,但不會評估其惡意意圖。

一旦以內核級別權限執行,該簽核驅動程式便終止了145種不同安全產品的進程,移除了受影響系統上的端點防禦。安全監控被解除後,信息竊取程式得以在未被察覺的情況下收割敏感用戶數據。

安全研究人員觀察到,此次事件的目標是信任機制,而非利用傳統的軟件漏洞。微軟的驅動程式簽核計劃旨在向用戶保證軟件的來源和相容性,卻反而成為繞過安全控制的載體。研究人員指出,經簽核的執行檔並不能保證安全行為,這挑戰了用戶和管理員的普遍假設。

完整報告可在Security Affairs查閱。

新聞來源 / Original News Source