Back to all news
Security

Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

The Hacker News·September 21, 2026·1 min read
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

A fake LastPass Authenticator installer on GitHub installs a Windows kernel driver that disables antivirus and security software before a password stealer runs, researchers at LastPass and Delphos Labs said on September 17. Microsoft's hardware-compatibility program signs the driver, which scored zero detections on VirusTotal when researchers tested it.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store