How the Scam Works Mechanically

This sophisticated phishing campaign leverages malicious GitHub repositories designed to mimic legitimate software providers, most notably LastPass Authenticator, but also impersonating at least 39 other companies. The attackers optimize these repositories for search engines, making them appear in search results when users look for popular software. When a user clicks on a download link within these fake repositories, they are subjected to a series of redirects that ultimately lead to payload-delivery servers. Here, victims download ZIP archives. These archives are intentionally inflated in size, sometimes up to 148MB, to evade detection by security software. Inside these archives is a disguised installer, masquerading as a legitimate Microsoft Visual Studio debugger ('vsdbg.exe'). This installer, however, is configured to load a malicious DLL ('vsdbg.dll') which then deploys two key components: the Rapuncel information stealer and a kernel driver named Alinubx.sys. The driver is disguised as an NVIDIA component ('nvfsflt64.sys') and operates as a service to disable a wide array of antivirus and endpoint detection and response (EDR) products, creating a window of opportunity for the infostealer.

Warning Signs & Red Flags

  • Search results leading to GitHub repositories for software downloads, especially for tools like authenticator apps.
  • Unusually large download file sizes for seemingly simple software.
  • Download links that redirect through multiple, unfamiliar URLs before reaching the actual download.
  • Software installers that appear to be legitimate but are downloaded from unofficial or suspicious sources.
  • Antivirus or security software suddenly becoming inactive or reporting errors after installing new software.
  • Unexpected system behavior or performance issues following a software installation.

How to Protect Yourself & Report

To safeguard yourself from such threats, it is crucial to adhere to safe downloading practices. Always download software directly from the official website of the developer or vendor. Be highly skeptical of links found through search engines, particularly those leading to code repositories like GitHub for end-user applications. Avoid clicking on promoted or sponsored links in search results, as these can sometimes be compromised. If you encounter a suspicious repository or download, report it to the platform (e.g., GitHub) and to the legitimate company being impersonated. Ensure your operating system and all security software are kept up-to-date, as these updates often include patches for vulnerabilities and improved detection capabilities. Regularly review your installed applications and remove any that you do not recognize or no longer need.