China-nexus actor steals thousands of documents in monthslong exploitation campaign
10 Articles
10 Articles
China-nexus actor steals thousands of documents in monthslong exploitation campaign
Researchers suspect the hacker employed LLMs to develop custom tools.
China-nexus actor steals thousands of documents in monthslong exploitation campaign | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker - National Cyber Security Consulting
A Chinese-speaking threat actor has engaged in a hacking campaign at least since June, involving the theft of thousands of documents from, at minimum, one Western government, according to a Monday blog post from threat intelligence firm GreyNoise. The hacker targeted critical vulnerabilities in multiple technologies, including WordPress, Zyxel and Ubiquiti, and is suspected of […] Thank you for subscribing to our RSS feed!
A fake LastPass Authenticator installer is being used in a sophisticated campaign to distribute malware capable of deactivating antivirus and EDR solutions in Windows. The attack combines fraudulent pages hosted in GitHub, SEO poisoning techniques, DLL lateral loading and exploitation of a vulnerable kernel driver for high privileges. The campaign analyzed by LastPass and Delphos Labs uses Rapuncel malware, an infostealer designed to steal crede…
Fake LastPass Installer Disables Antivirus With Microsoft Driver
Researchers at LastPass and Delphos Labs identified a malicious LastPass Authenticator installer distributed via a fake GitHub repository that ranks high in search results. The attacker created a counterfeit page at github.com/LastPass-Authenticator designed to appear legitimate to users searching for LastPass Authenticator downloads. Users clicking the download button are redirected through multiple GitHub pages to […]
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17. Microsoft's own hardware-compatibility program signs the driver, scored zero detections on VirusTotal when researchers
A campaign that appeared to offer official tools from LastPass used fake repositories in GitHub to distribute Rapuncel, an infostealer capable of stealing credentials, sessions, crypto wallet data and sensitive documents. The operation also incorporated a signed controller that could terminate antivirus and EDR processes from kernel mode, turning a seemingly reliable download into a high-impact intrusion.
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium








