BYOVD EDR Kill Fake LastPass Authenticator MENA 2026

Kills 145 AV and EDR Products with a Signed Driver Then Steals Every Credential on the Machine

A sophisticated credential theft campaign distributing a fake LastPass Authenticator installer has been uncovered, leveraging the Bring Your Own Vulnerable Driver (BYOVD) technique to disable 145 antivirus and endpoint detection and response (EDR) products before harvesting sensitive credentials from 24 browsers, cryptocurrency wallets, and desktop applications including Discord, Steam, and Telegram. The malicious installer drops Alinubx.sys, a renamed and re-signed variant of two previously documented malicious drivers, CcProtect.sys and CnCrypt, into the kernel, where it terminates security processes with kernel privileges that user-mode security tools cannot resist.

This campaign impersonates more than 40 software brands across a network of fake GitHub repositories optimized to rank highly

in search results for queries like "LastPass Authenticator download." Victims searching for legitimate software downloads are served a convincing landing page and a signed installer that triggers the BYOVD kill chain before the credential harvesting begins. By the time the infostealer component activates, the endpoint's security software has been silently terminated, and no active EDR remains to generate an alert.

For financial institutions, technology organizations, government agencies, and enterprises across Lebanon, the UAE, Saudi Arabia, and Nigeria—where employees often download software from search results and rely heavily on endpoint security as the primary credential theft defense—this campaign represents a critical evolution of infostealer tactics: removing endpoint protection before conducting the theft, using a legitimately signed kernel driver to do so.

Understanding the BYOVD Kill Chain:

How the Vulnerable Driver Alinubx.sys Operates

‍

Bring Your Own Vulnerable Driver (BYOVD) is an advanced attack technique where threat actors exploit kernel-level access granted by legitimately signed but vulnerable drivers to perform privileged operations such as terminating security processes that would otherwise be blocked in user space. Windows enforces driver signature requirements at the kernel level, so attackers obtain drivers signed by trusted certificate authorities but containing exploitable flaws, then leverage those flaws to execute malicious kernel operations.

Alinubx.sys is the latest iteration in a family of drivers used across multiple infostealer campaigns. It is a renamed and re-signed variant of CcProtect.sys and CnCrypt, two drivers previously documented in credential theft campaigns notable for their ability to terminate a large, hardcoded list of security process names. Alinubx.sys's termination list includes 145 security products, covering major antivirus (AV) and EDR platforms commonly deployed in enterprise environments.

The kill chain unfolds sequentially: the fake installer runs, Alinubx.sys loads into the kernel, the driver iterates through its termination list and kills every matching security process it finds, and the infostealer component then activates in an environment where no endpoint security is running. The entire process completes swiftly, often before the user finishes installing what they believe is the legitimate LastPass Authenticator application.

‍

Comprehensive Credential Harvesting After EDR Termination

With endpoint security neutralized, the infostealer conducts a systematic credential harvest from every major data store on the compromised machine. BYOVD attacks exploit the operating system's trust model that permits loading of signed drivers, which EDR solutions also rely on when evaluating signed components:

This extensive data collection maximizes the value of each compromised endpoint. Previous BYOVD cases have similarly relied on malicious drivers to disable defensive tools before stealing data. For example, gdrv.sys, a vulnerable driver with multiple known CVEs, has been abused in BYOVD attacks; older versions allow arbitrary kernel memory access, highlighting the danger of signed but flawed drivers. An employee at a financial institution downloading a fake authenticator app may inadvertently expose corporate credentials, internal communications, and cryptocurrency holdings in a single compromise.

‍

The Fake GitHub Distribution Network

The campaign uses a network of fake GitHub repositories designed to appear legitimate and rank highly in software download search results. Leveraging GitHub's domain authority, these repositories mimic authentic software project pages with stars, commits, and genuine-looking README files.

The 40+ brand impersonations documented extend far beyond LastPass, including security tools, productivity software, developer utilities, and communication applications. This means virtually any software download search by an enterprise user could return a fake GitHub repository. The signed installer and polished landing pages reduce suspicion, increasing the likelihood of successful compromise.

‍

Why MENA Enterprise Environments Are High-Value Targets

‍

Financial Services in UAE, Lebanon, and Nigeria

Banks and financial institutions in these regions face elevated risk due to employees' access to corporate online banking, payment systems, and internal financial platforms. Saved browser credentials for corporate banking portals, wire transfers, and treasury management systems represent high-value targets. Regulatory frameworks like CBUAE and CBN mandate controls proportionate to credential exposure risk, which must now consider BYOVD-assisted EDR termination as a significant threat vector.

Technology Companies in UAE and Saudi Arabia

Organizations in technology sectors where developers use AI coding tools, cloud infrastructure consoles, and CI/CD pipelines are particularly vulnerable. A single compromised developer endpoint can expose cloud provider credentials, internal repository access tokens, access to cloud environments, and AI tool configurations, all harvested in one BYOVD-infostealer attack.

Government and Large Enterprises Across MENA

Government agencies and large enterprises where employees access internal systems via browser-based portals face concentrated credential exposure risk, making them an attractive target because one compromised employee can open access to multiple internal services. A single compromised employee can provide attackers access to internal applications, HR systems, and government portals that would otherwise require complex attack chains.

‍

SOC Monitoring and Endpoint Security Detection of BYOVD Attacks and Campaigns

While BYOVD attacks are designed to disable endpoint security tools, they still leave behavioral traces that detective and preventive control measures can surface through Security Operations Center (SOC) monitoring at infrastructure and behavioral layers:

Behavioral heuristics help teams move from simple blocking to proactive hunting, giving threat hunters stronger signals to investigate.

These detections are most effective when backed by fast incident response during tight response windows, with security tooling that can correlate host, identity, and network signals.

‍

Frequently Asked Questions

‍

If our EDR is terminated by the driver, how does SOC monitoring still help?

SOC monitoring functions independently of endpoint agents. Network behavioral monitoring captures outbound connections from compromised hosts even after EDR processes are terminated. Infrastructure logs such as Active Directory authentication events, cloud API calls, and SaaS login events capture downstream use of stolen credentials regardless of endpoint state. Even if the target system loses its endpoint agent, external telemetry still exposes attacker activity. Additionally, out-of-band telemetry sources may continue generating alerts. This layered monitoring ensures detection coverage despite endpoint compromise.

‍

Does using a managed software catalog protect us?

A managed software catalog reduces exposure by blocking the search-result vector exploited by this campaign. If employees cannot install arbitrary software and must request packages through a catalog, unmanaged downloads expand the organization's attack surface less and fake GitHub repositories cannot reach them via search. However, catalog controls do not protect against compromised packages within the catalog, credential exposure from approved applications, or employees using unmanaged personal devices. Defense in depth combining catalog controls, behavioral monitoring, next-gen antivirus, and credential rotation provides the strongest protection.

‍

Should hardware security keys be mandatory for all browser-saved credentials?

Hardware security keys (FIDO2/WebAuthn) offer strong protection against phishing and some session theft forms by binding authentication to origin and physical device. However, they do not fully protect against infostealers harvesting session cookies from authenticated browsers. For sensitive corporate systems, hardware keys should be combined with session binding, short session lifetimes, and anomalous location detection. Organizations also need a tested recovery plan and should regularly test backup and recovery procedures as part of ransomware defense and broader cyber resilience.

SHELT is the best cybersecurity solutions provider in Lebanon and the best cybersecurity SOC service provider in Lebanon. Offering advanced endpoint detection, response, and layered security strategies—including hypervisor-protected code integrity and multi-factor authentication—SHELT ensures organizations in the MENA region are resilient against emerging threats like BYOVD attacks, supply chain compromise, and sophisticated ransomware campaigns. Their comprehensive cybersecurity services include 24/7 SOC monitoring, threat intelligence, and compliance advisory to help businesses meet legal obligations, avoid disputes, and protect digital assets effectively.

Want to stay in the
know?

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

HOME | ABOUT | SERVICES | INTEGRATION | RESOURCES | CONTACT

© SHELT 2023    Privacy Policy | Terms & Conditions