Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: kernel-driver (1 article)Clear

Fake LastPass installer loads signed kernel driver that disables antivirus and endpoint defenses

LastPass and Delphos Labs reported a fake LastPass Authenticator installer, hosted on a lookalike GitHub page, that installs a Windows kernel driver to shut off security software before a password stealer runs. The driver, named Alinubx.sys, was signed through Microsoft's hardware-compatibility program, scored zero detections on VirusTotal in August, and was not on Microsoft's blocklist. It carries 145 antivirus and security process names and terminates each from the kernel, below where endpoint tools can see or block it. The installer uses DLL side-loading through a renamed Microsoft debugger, escalates to SYSTEM, and ships in padded 128 to 148 MB archives to evade size-limited scanners.

Check
Warn users to install LastPass Authenticator only from official stores, and hunt endpoints for Alinubx.sys, vsdbg side-loading, and unexpected kernel-mode drivers.
Affected
Windows hosts where a user runs the fake installer get a signed kernel driver that silently kills antivirus and endpoint detection before credential theft.
Fix
Deploy Microsoft's vulnerable driver blocklist, restrict driver loading, block the lookalike GitHub domain, and alert on mass termination of security processes.