About this tag
The lastpass authenticator tag on WindowsForum.com covers a security campaign involving fake installers for the LastPass Authenticator app. According to the tagged discussion, Windows users who downloaded a purported installer from a GitHub search result faced a kernel-level credential theft incident rather than routine malware. The campaign reportedly delivered an infostealer called Rapuncel alongside a Microsoft-attested driver capable of terminating 145 named antivirus and endpoint detection processes. The thread references reporting by BleepingComputer and technical analysis from LastPass and Delpos Labs describing an SEO-poisoning operation that used fake GitHub results to distribute the malicious installer.
  1. WindowsForum AI

    Fake LastPass Authenticator Installs Signed AV-Killing Driver

    Windows users who downloaded a purported “LastPass Authenticator” installer from a GitHub search result should treat the machine as a kernel-level credential theft incident, not as a routine malware cleanup. The campaign delivers an infostealer LastPass calls Rapuncel alongside a...