BlackTree Security · Infrastructure · Automation · AI

The Fake GitHub Download Arrived With a Microsoft-Signed EDR Killer

The download page looked like GitHub. The driver carried Microsoft’s attestation. Neither fact made the software safe. Rapuncel combines search-optimised repositories impersonating more than 40 brands with a kernel driver designed to terminate the security products that could stop its credential theft.

Research from LastPass and Delphos describes external repositories that lure users searching for popular applications. No LastPass service or vault was breached. The company analysed the campaign because one of the copied brands and delivery paths could mislead its users.

The trusted driver became the security-control killer

Rapuncel’s driver is Microsoft-attested and operates in the Windows kernel. The malware uses that privileged position to target 145 named endpoint and security products. This is a trusted-component abuse pattern: the attacker does not need to exploit the security tool itself if an accepted driver can interfere with its processes.

The report also describes browser and cryptocurrency-wallet theft. Some stealth features were present in the analysed driver but were not activated in the observed deployment. That distinction should remain visible. Capability in code is not proof that every function ran on every victim.

Search results are part of the delivery chain

The repositories were built to catch users searching for legitimate software. A familiar brand, professional README and GitHub URL can create enough confidence to run an installer. The attacker then benefits from two borrowed reputations: the repository platform at delivery time and Microsoft’s driver attestation at execution time.

Attestation is not a permanent judgement that every action by a driver is benign. It establishes a signing and submission history, but a signed component can still be vulnerable, abused or intentionally harmful. Defenders need behavioural controls and revocation paths in addition to signature validation.

Defensive actions

  • Use the vendor’s real distribution path. Do not obtain enterprise or wallet software from a repository found through an advertisement or generic search result.
  • Control driver loading. Apply Microsoft-recommended vulnerable-driver blocking and allow-listing where operationally possible.
  • Alert on security-process termination. Multiple EDR services failing together is a high-value incident signal.
  • Inspect the whole host. Reinstalling the intended application does not remove a kernel driver or stolen browser session.
  • Rotate exposed credentials. Treat browser tokens, wallet material and developer secrets present on the host according to evidence.
  • Hunt by behaviour. Repository names and domains change faster than driver-loading, process-killing and credential-access patterns.

Rapuncel is a reminder that trust marks are inputs to a decision, not the decision itself. A known platform and a valid signature can both be real while the software they help deliver is hostile.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *