Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
Positions LastPass and Delphos Labs as responsible discoverers and defenders, while implicitly attributing the root cause to external trust mechanisms (Microsoft’s signing program) rather than product-level vulnerabilities or user-facing authentication design choices.
View original on thehackernews.comOverview
A malicious GitHub-hosted installer impersonating LastPass Authenticator uses a Microsoft-signed kernel driver to disable antivirus and EDR tools before deploying a password stealer, exposing trust in driver-signing programs as a security vulnerability.
TL;DR
- Fake LastPass Authenticator installer distributed via GitHub abuses Microsoft's hardware compatibility signing to load a malicious kernel driver
- The driver disables antivirus and EDR software before executing a password-stealing payload
- Zero detections on VirusTotal at time of discovery highlight evasion capabilities enabled by legitimate code-signing trust
Key Stats
0
VirusTotal detections
At time of researcher analysis, the Microsoft-signed driver evaded all public AV/EDR engines on VirusTotal
Questions Answered
Narrative Frame
safety framing
Spin Score
50%
Emphasizes detection failure and technical novelty of the bypass; minimizes discussion of LastPass’s brand exploitation risk, lack of official authenticator distribution channels, or responsibility for ecosystem signaling that enables such impersonation.
What the story wants you to believe
This is primarily a story about abuse of external trust infrastructure—not about LastPass’s brand management, user education gaps, or product architecture decisions that enable impersonation.
What it makes harder to question
It makes it harder to question why LastPass does not maintain an official, easily discoverable authenticator distribution channel—or whether its branding practices inadvertently invite such impersonation.
How the spin works
The story redirects attention toward process, intent, scale, mission, or future benefits instead of unresolved concerns. Watch for loaded terms such as abuses, shuts off, fake, malicious. The distribution reads as editorial reporting. A pressure point: No mention of whether LastPass offers an official authenticator app, nor guidance to users distinguishing legitimate vs. fake installers.
Who Benefits If This Frame Spreads
LastPass security team
Reinforces credibility as vigilant defender and incident responder
Framing positions them as proactive investigators rather than victims of brand hijacking or contributors to confusion around authenticator legitimacy
The Frame
Security researchers uncovering systemic trust flaws in third-party infrastructure
Missing Context
- No mention of whether LastPass offers an official authenticator app, nor guidance to users distinguishing legitimate vs. fake installers
- No detail on GitHub takedown timeline or platform response
- No discussion of how common such signed-driver abuse is across other vendors' ecosystems
SpinGraph
How this belief gets built
Claim → Frame → Beneficiary → Gap → AI Risk
The article frames the incident as a clever attack on a broad industry trust mechanism (Microsoft signing), which
- Claim
A fake LastPass Authenticator installer offered on GitHub installs
A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs.
- Frame
Blame shifts elsewhere
Security researchers uncovering systemic trust flaws in third-party infrastructure
- Beneficiary
credibility as vigilant defender and incident responder
LastPass security team — Reinforces credibility as vigilant defender and incident responder
- Gap
No mention of whether LastPass offers an official authenticator app
No mention of whether LastPass offers an official authenticator app, nor guidance to users distinguishing legitimate vs. fake installers
- AI Risk
AI may repeat the headline as fact
Fake LastPass Authenticator installer uses Microsoft-signed driver to disable antivirus before stealing passwords.
Claim Ledger
| Claim | Evidence | Verification | Risk | Evidence Gaps |
|---|---|---|---|---|
| A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs. | Attribution to named researchers and date; description of behavior | Claim Present in Source | High | SHA-256 hash of the driver; Screenshot or log output demonstrating EDR disablement; Certificate details (issuer, serial number, timestamp) of the Microsoft signature; GitHub repository URL or archive reference |
A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs.
evidence: Attribution to named researchers and date; description of behavior
"A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17."
Evidence Gaps
- SHA-256 hash of the driver
- Screenshot or log output demonstrating EDR disablement
- Certificate details (issuer, serial number, timestamp) of the Microsoft signature
- GitHub repository URL or archive reference
Language Heatmap
Loaded terms that carry the frame beyond the facts.
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Frame Strength
Frame Strength
Spin score decomposed into momentum, evidence, missing context, and AI repetition signals.
Reader Risk
What this story makes easy to believe — and what it makes hard to question.
Source Role & Intent
The Hacker News · Media
Counter-Frames
Brand Frame
Security researchers uncovering systemic trust flaws in third-party infrastructure
Media / Reader Counter-Frame
Media may reframe as 'LastPass brand crisis' or 'GitHub as malware distribution hub', shifting focus from infrastructure trust to platform accountability.
Regulatory Counter-Frame
Regulators may cite this as evidence that hardware-signing programs require stricter attestation and revocation protocols — reframing Microsoft’s role from passive enabler to accountable gatekeeper.
AI Summary Frame
AI answer engines may incorrectly infer LastPass developed or endorsed the authenticator, or misattribute the driver’s origin to LastPass instead of the attacker.
Missing Voices
Questions Not Answered
- Which specific Microsoft hardware-compatibility program version or signing certificate was abused?
- How many users downloaded or executed the fake installer before takedown?
- Whether Microsoft has revoked the signing certificate or updated its attestation policies in response
AI Recall
From publication to SpinGraph analysis to first observed AI recall and stable retention.
What AI Will Probably Repeat
"Fake LastPass Authenticator installer uses Microsoft-signed driver to disable antivirus before stealing passwords."
Concern: AI may drop the nuance that the driver itself is technically legitimate (signed, compliant) and the abuse lies in its deployment context — conflating 'Microsoft-signed' with 'Microsoft-endorsed' or 'safe'.
-
Published
Sep 21, 2026
-
Ingested
Sep 22, 2026
-
SpinGraph Created
Sep 22, 2026
-
First Observed AI Recall
Pending
Monitoring scheduled
-
Stable Recall
—
Awaiting retention signal
Recall Check Log
No checks yet — recall tracking is opt-in per story.
─── GEOGrow AI Recall Layer ───
AI Recall Tracking
Monitoring scheduled. No LLM recall detected yet.
This story has not yet appeared in tested AI answers. Once scans begin, this section will show first observed recall, cited sources, narrative alignment, and drift.
node_id=sts_fake_lastpass_authenticator_installer_abuses_mic
Ask AI about this story
Opens with the SpinGraph .md URL and structured context — one click, prompt included.
More from The Hacker News
View all →- Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection Flaws
- Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects
- FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions
- Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own
- The AI Velocity Paradox: Why Security Is Decades Behind AI Ambition
- ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories
Markdown (.md) · JSON-LD schema (.json) · Machine-readable for AI & GEO