HomeIntelligenceBrief
BREACH BRIEF 🟠 High ThreatIntel

Fake LastPass Authenticator Installer Deploys Microsoft‑Signed Kernel Driver to Disable AV/EDR

A counterfeit LastPass Authenticator installer on GitHub drops a Microsoft‑signed kernel driver that shuts down antivirus and EDR before running a password‑stealer. The incident underscores the need for continuous monitoring of signed drivers and third‑party risk oversight in a control‑assurance program.

Verisq™ Intelligence · 📅 September 22, 2026 · 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
thehackernews.com

Fake LastPass Authenticator Installer Deploys Microsoft‑Signed Kernel Driver to Disable AV/EDR

What Happened — Researchers discovered a counterfeit “LastPass Authenticator” installer on GitHub that drops a Windows kernel‑mode driver. The driver is signed through Microsoft’s hardware‑compatibility program, evades VirusTotal detection, and disables antivirus and endpoint‑detection‑and‑response (EDR) solutions before launching a password‑stealing payload.

Why It Matters for Trust & Control Assurance

  • Demonstrates how reliance on code‑signing alone can be subverted, highlighting the need for continuous monitoring of driver load events and verification of signed binaries.
  • Tests the control objective of software and hardware supply‑chain security—a single satisfied control can satisfy many frameworks (e.g., NIST CSF 2.0, ISO 27001).
  • Aligns with Verisq’s Vendor Risk Management capability: continuous oversight of third‑party components (including Microsoft‑signed drivers) provides defensible audit evidence of due diligence.

Who Is Affected – Primarily identity‑and‑access‑management (IAM) vendors and their enterprise customers, but any organization that permits driver installation on Windows endpoints is at risk.

Recommended Actions

  • Enforce strict application‑control policies that block unsigned or unapproved kernel drivers.
  • Deploy real‑time driver‑load monitoring and integrate alerts into your SIEM.
  • Incorporate signed‑driver verification into your third‑party risk assessments and maintain evidence of vendor due‑diligence.
  • Conduct periodic “driver hygiene” audits to ensure only approved, vetted drivers are present.

Source: The Hacker News

Technical Notes – The malicious driver is delivered via a fake installer (social‑engineering vector), leverages a legitimate Microsoft code‑signing certificate, and disables AV/EDR before executing a credential‑stealing module. No CVE is associated; the attack exploits trust in signed code rather than a software flaw. Source: same as above

📰 Original Source
https://thehackernews.com/2026/09/fake-lastpass-authenticator-installer.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →