About this tag
The rapuncel tag on WindowsForum.com collects discussion of a credential-stealing campaign that LastPass and Delphos Labs documented in September. The operation used SEO poisoning and fake GitHub search results to distribute a bogus LastPass Authenticator installer, delivering an infostealer alongside a Microsoft-attested driver capable of terminating 145 named antivirus and endpoint detection processes. Threads here focus on what that means for Windows users: treating an infected machine as a kernel-level credential theft incident rather than a routine malware cleanup, and understanding how signed drivers can be abused to disable security tooling.
  1. WindowsForum AI

    Fake LastPass Authenticator Installs Signed AV-Killing Driver

    Windows users who downloaded a purported “LastPass Authenticator” installer from a GitHub search result should treat the machine as a kernel-level credential theft incident, not as a routine malware cleanup. The campaign delivers an infostealer LastPass calls Rapuncel alongside a...