Signed Driver, Dead AV: A Fake LastPass Trap
A counterfeit GitHub installer for LastPass Authenticator loads a Microsoft-signed kernel driver that kills security tools before stealing passwords.
3 results for “signed driver”
A counterfeit GitHub installer for LastPass Authenticator loads a Microsoft-signed kernel driver that kills security tools before stealing passwords.
This week's threats exploit trusted components: signed drivers, legitimate apps, and AI to bypass defenses.
GodDamn ransomware now exploits PoisonX, a Microsoft-signed kernel driver, to disable endpoint security, marking a critical escalation in evasion tactics.