Attackers used a Microsoft-attested Windows driver to disable 145 security tools
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Monday, September 21st, 2026.
Victims could lose passwords, browser sessions, and cryptocurrency data after a malware campaign used a trusted-looking Windows driver to disable endpoint protection. Attackers created fake GitHub pages that impersonated LastPass Authenticator, although LastPass systems, services, and customer vaults were not compromised. The downloaded payload deployed a Microsoft-attested Windows kernel driver with 145 hardcoded process names associated with antivirus and endpoint security products. After weakening those defenses, the Rapuncel information stealer targeted saved passwords from more than 25 browsers, cryptocurrency wallet files, browser sessions, application tokens, screenshots, and sensitive documents. A valid-looking signature can make dangerous code appear trustworthy and help it reach the Windows kernel. Anyone who ran the fake installer should assume credentials stored on that device were exposed. Defenders should monitor unusual driver loads, the mass termination of security tools, renamed Microsoft executables, and oversized downloads from suspicious GitHub pages. Isolate affected devices and rotate passwords, sessions, wallet secrets, and tokens from a separate, known-clean system.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.