HomeSecurityFake LastPass Authenticator installer exploits Microsoft signed driver

Fake LastPass Authenticator installer exploits Microsoft signed driver

A fake LastPass Authenticator offered on GitHub installs a Windows kernel driver that disables antivirus and other security software before a password stealer can execute if a victim downloads and executes it, researchers at LastPass and Delphos Labs on Sept. 17.

See also: Phishing campaign misuses LastPass name – Company denies breach

Article Image: Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
Fake LastPass Authenticator installer exploits Microsoft signed driver

Microsoft’s Hardware Compatibility Program signs the driver, which was not detected at all on VirusTotal when checked in August and was not on Microsoft’s list of blocked drivers. LastPass said that none of its customer systems, services, or vaults were affected, and that the attackers only used its name. The decoy is a fake page on GitHub (github.com/LastPass-Authenticator) that appears in search results for terms like “LastPass Authenticator download” and looks like a legitimate LastPass product page.

By clicking the download button, the visitor is redirected through several GitHub pages to an attacker's server, which provides a large ZIP file. The original LastPass Authenticator is available from lastpass.com and official app stores, not from GitHub.

Inside the ZIP file is a renamed copy of a legitimate Microsoft debugging tool, vsdbg.exe, along with a malicious file named vsdbg.dll. When the fake installer is run, Windows loads the attacker's DLL from the same folder, a technique known as DLL side-loading. The loader then attempts three methods to gain administrative privileges, reaches the SYSTEM level, the highest level of privilege on a Windows machine, and installs the kernel driver as a service. The files observed were 148 MB and 127.9 MB, filled with junk files to evade scanners with size limits.

A kernel driver runs below the level where antivirus and endpoint detection and response (EDR) tools operate. This driver, named Alinubx.sys by the researchers, contains a list of 145 antivirus and security process names and terminates any that it detects as running.

See also: Microsoft Authenticator: End of password support from August

Fake LastPass Authenticator installer exploits Microsoft signed driver
Fake LastPass Authenticator installer exploits Microsoft signed driver

It does this from the kernel, below the level where security software operates, preventing user-level tools from blocking or detecting the termination. Using a legitimately signed but exploitable driver to gain this access is a well-known technique called “bring your own vulnerable driver” (BYOVD).

The driver is signed via the Microsoft Windows Hardware Compatibility Publisher, with a signing date of March 2023, prior to this campaign. As the researchers noted, “Microsoft certification proves that a driver has passed through a chain of trust. It does not prove that the driver is safe.

The kill list is the only functionality of the driver that was used. Its code can also hide files, inject itself into other programs, and redirect internet traffic, but these capabilities require a configuration file that the attackers did not include.

With security software disabled, the thief collected saved passwords from over two dozen browsers, cryptocurrency wallet files, and login sessions for Discord, Steam, and Telegram, along with the contents of Windows Credential Manager and files named “password,” “seed,” or “recovery.”.

For Chrome and Edge, which use Google's App Encryption to prevent this type of attack, the thief injects code into the browser and asks the browser's service to decrypt the passwords. The data is then packaged into a ZIP file and sent to an attacker's server.

The driver is a renamed copy of CcProtect.sys, a driver from the Chinese disk encryption product CnCrypt that is already listed on the LOLDrivers directory as a process killer, with public proof-of-concept code. The two share the same product name, version, and subdirectory. Only the file name and description have been changed. This change has reduced the file's detections by antivirus: the known original showed 7 out of about 70 machines flagging it in August, while the renamed driver showed zero detections.

See also: Microsoft Authenticator: Automatically blocks suspicious MFA notifications

Fake LastPass Authenticator installer exploits Microsoft signed driver

Microsoft's Vulnerable Driver Block List, which has been enabled by default since the Windows 11 2022 Update, prevents registered drivers from loading. Delphos checked on August 20th and found neither the original nor the renamed driver registered.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS