#Delphos
🟢 Fake LastPass Authenticator Repositories on GitHub Contain Rapuncel Stealer

🗨️ Researchers at LastPass and Delphos Labs have uncovered a large-scale malicious campaign in which attackers publish GitH…

#news
Fake LastPass Authenticator Repositories on GitHub Contain Rapuncel Stealer
Read more
hackmag.com
September 28, 2026 at 10:04 AM
I'm definitely out of my depth here, and forgive me for referring to Wikipedia, but I think this section explains why he would've called it "an-"
September 26, 2026 at 12:02 AM
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs…
#hackernews #microsoft #news
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17. Microsoft's own hardware-compatibility program signs the driver, scored zero detections on VirusTotal when researchers
thehackernews.com
September 22, 2026 at 6:24 PM
Onderzoekers ontmaskeren malwarecampagne die zich voordeed als LastPass Authenti

Onderzoekers van LastPass Threat Intelligence, Mitigation, and Escalation, in samenwerking met Delphos Labs, hebben een malwarecampagne ontdekt genaamd Rapuncel. De aanvallers deden zich voor als LastPass Authe...
Onderzoekers ontmaskeren malwarecampagne die zich voordeed als LastPass Authenticator
Onderzoekers van LastPass Threat Intelligence, Mitigation, and Escalation, in samenwerking met Delphos Labs, hebben een malwarecampagne ontdekt genaamd Rapuncel. De aanvallers deden zich voor als LastPass Authenticator en creëerden valse GitHub-pagina's die de officiële downloadpagina's nabootsten, om zo legitiem te lijken in zoekresultaten. Gebruikers die zochten naar LastPass Authenticator download konden een valse GitHub-organisatie vinden met een downloadknop. Het klikken op deze knop leidde bezoekers via meerdere GitHub Pages-sites naar door aanvallers gecontroleerde infrastructuur. De aanvallers gebruikten verborgen omleidingspagina's op GitHub en een door Cloudflare beschermde laag...
newsfacts.info
September 21, 2026 at 12:00 PM
Special Weather Statement issued September 20 at 1:46AM CDT by NWS Topeka KS
Additional Details Here.
September 20, 2026 at 7:00 AM
All On invests in PowerGen to expand renewable energy access in Nigeria
Nigerian impact investor All On has made a strategic investment in PowerGen Renewable Energy, supporting the expansion of the company’s renewable energy operations across Nigeria. Delphos, which acted as PowerGen’s exclusive financial adviser, supported the transaction through its structuring, negotiation and execution. The investment will provide growth capital for PowerGen’s commercial and industrial (C&I) business as well as its distributed utility operations. The funding is expected to support the development of additional renewable energy infrastructure and expand access to reliable, affordable and lower-carbon electricity for businesses and communities. The deal comes after PowerGen completed a major capital raise in 2025 involving a consortium of development finance institutions (DFIs) and private investors. Delphos also advised PowerGen on an investment from Denmark’s development finance institution, IFU, as part of that financing round. Founded in 2016, All On is an impact investor focused on increasing access to commercial energy in Nigeria, with investments across the country’s distributed energy sector. For PowerGen, the latest investment adds to its efforts to scale its renewable energy platform in Nigeria and strengthen its presence in Africa’s growing distributed energy market. “This investment from All On is a strong vote of confidence in PowerGen's platform and our ability...
www.africanews.com
September 20, 2026 at 2:47 AM
The 69th annual Delphos Canal Days festival featured food, games, and fundraisers to support the local community.
Delphos Canal Days continues to support the community with a lot of fun, food, and activities
The 69th annual Delphos Canal Days continued Saturday with basket bingo, raffles, purse bingo, live entertainment and activities for the community.
www.hometownstations.com
September 20, 2026 at 2:24 AM
Severe Thunderstorm Warning issued September 19 at 6:16PM CDT until September 19 at 6:45PM CDT by NWS Topeka KS

At 616 PM CDT, a severe thunderstorm was located 6 miles northeast of
Delphos, moving east at 25 mph.

HAZARD...60 mph wind gusts and half dollar size hail...

#Thunderstorm #wx
September 19, 2026 at 11:31 PM
🚨 Severe Thunderstorm Warning issued September 19 at 6:16PM CDT until September 19 at 6:45PM CDT by NWS Topeka KS 🚨
Additional Details Here.
September 19, 2026 at 11:30 PM
Special Weather Statement issued September 19 at 5:40PM CDT by NWS Topeka KS
Additional Details Here.
September 19, 2026 at 10:45 PM
Delphos Advises PowerGen on Strategic Investment from All On to Expand Energy Access Across Nigeria
WASHINGTON D.C., US - Media OutReach Newswire – 17 September 2026 – Delphos is pleased to announce the successful closing of a strategic investment in PowerGen Renewable Energy ("PowerGen") by All On Partnerships for Energy Access Limited by Guarantee ("All On"), a leading Nigerian impact investor dedicated to expanding access to commercial energy across the country. Delphos acted as an exclusive financial advisor to PowerGen, supporting the company throughout the structuring, negotiation and successful execution of the transaction. The funding will support the continued expansion of PowerGen's renewable energy platform in Nigeria, providing growth capital for both its commercial and industrial ("C&I") business and distributed utility operations. The investment will fund additional renewable energy infrastructure, delivering reliable, affordable and lower-carbon electricity to businesses and communities, and is expected to support up to 6,000 electricity connections and reach an estimated 41,000 beneficiaries across Nigeria. The transaction follows PowerGen's successful landmark capital raise completed in 2025. The fundraising brought together a consortium of leading development finance institutions (DFIs) and private investors, reflecting continued investor confidence in the company's growth strategy, operating model, and management team. As part of the financing round, Delphos advised PowerGen on the investment from IFU, Denmark's development finance...
www.zawya.com
September 19, 2026 at 12:29 PM
Rapuncel: Fake GitHub Repositories Disable EDR with a Signed Kernel Driver
## 1. Basic Information * Original Title: Threat Intel | One Kit, Forty Companies: How a Malware-as-a-Service Platform Used GitHub as a Distribution Network for its Campaign * Source: LastPass TIME / Delphos Labs * Published Date: 2026-09-17 * Updated Date: None * Severity: High * Basis for Severity: An active distribution infrastructure impersonating over 40 companies uses a kernel driver with a Microsoft compatibility signature to terminate processes matching 145 built-in AV and EDR-related process names, while stealing credentials from browsers and cryptocurrency wallets. * Original Article: Threat Intel | One Kit, Forty Companies: How a Malware-as-a-Service Platform Used GitHub as a Distribution Network for its Campaign * Related Source: BleepingComputer Coverage * Related Entities: Rapuncel, Alinubx.sys, Cruciferra PUROSANGUE, BoryptGrab, GitHub Pages, Windows ## 2. Executive Summary This attack distributes large ZIP files through high-ranking fake GitHub repositories, uses DLL side-loading, and escalates privileges to SYSTEM. A signed kernel driver then terminates processes matching 145 built-in AV and EDR-related process names, after which Rapuncel steals credentials and other sensitive data. ## 3. Attack Flow ### From Search Results to Credential Theft 1. Users search for legitimate software and follow SEO-optimized links to fake GitHub repositories. 2. Users download a ZIP file padded to 127–148 MB via GitHub Pages 404 handling and dynamic redirects hosted behind Cloudflare. 3. A fake installer loads a malicious `vsdbg.dll` into the legitimate `vsdbg.exe` and obtains SYSTEM privileges through multiple UAC elevation techniques. 4. Alinubx.sys, deployed as `nvfsflt64.sys`, terminates processes matching 145 built-in AV and EDR-related process names from kernel mode. 5. Rapuncel collects data from browsers, cryptocurrency wallets, Discord, Steam, Telegram, and Windows Credential Manager, then sends it to `2.26.126[.]50`. 6. Persistence is established via a Windows service to continue stopping defense products and stealing data after reboot. ## 4. Attacker Location and Execution Environment * Attackers manipulate search visibility and externally operate fake GitHub repositories, GitHub Pages content, Cloudflare-hosted redirects, and payload servers. * After initial execution, the user-mode loader and Rapuncel, along with the kernel-mode Alinubx.sys, run on the victim Windows endpoint. ## 5. Victim and Administrator Perspective * **Victim** : Appears as a legitimate brand GitHub page, displays fake VirusTotal approval, and acts as a normal installer. * **Administrator** : Leaves traces such as an unknown DLL in the same directory as `vsdbg.exe`, the `NvFsFilter` service, `C:\Windows\System32\drivers\nvfsflt64.sys`, and numerous security process terminations. ## 6. Success and Failure Conditions ### Success Conditions * The user downloads and executes the ZIP from the fake repository, and grants or successfully achieves privilege escalation. * Driver deployment and service registration are permitted, and are not blocked by application control or driver blocks. ### Failure Conditions * Software distribution is restricted to official websites and managed stores, and unofficial distributions on GitHub are not executed. * The hash, signature family, device name, and service creation of Alinubx.sys are blocked, preventing unauthorized drivers. ## 7. What Happens Upon Success * Defense products are stopped, and saved credentials are decrypted by bypassing browser App-Bound Encryption. * Cryptocurrency wallets, session tokens, documents, screenshots, and system information are stolen. ## 8. Observable Logs * **Email** : No email distribution observed. * **Proxy / SWG / DNS** : Communication to fake GitHub Pages, dynamic redirects, payload servers, and `2.26.126[.]50` is observed. * **Endpoint / EDR** : Check for vsdbg.exe loading an unexpected vsdbg.dll, DLL side-loading, driver deployment, creation of the NvFsFilter service, and termination requests targeting numerous AV and EDR-related processes. * **Identity / IdP** : Usage of stolen browser, Discord, Steam, and Telegram sessions is observed. * **SaaS / Cloud** : Access to fake organizations and pages on GitHub cannot be confirmed via internal GitHub audit logs, so it is supplemented by Proxy/SWG or browser history. * **Network** : Transmission to `2.26.126[.]50` via HTTP format over raw TCP is observed. ## 9. Attack Success Determination ### Confirmed via Public Information * **Malware Execution or Authentication Success Confirmed** : LastPass and Delphos Labs analyzed the acquired samples and confirmed the operation of Rapuncel, Alinubx.sys, and browser injection DLLs. The number of affected endpoints has not been publicly disclosed. ### Internal Organization Criteria * **User Action Confirmed** : Evidence of downloading and extracting the ZIP from the fake repository is confirmed. * **Initial Execution Confirmed** : Malicious DLL loading by `vsdbg.exe`, SYSTEM privilege escalation, and driver service registration are substantiated. * **Information Theft or Session Compromise Confirmed** : Generation of collected files, C2 transmission, and usage of stolen sessions are confirmed. ## 10. Investigation Playbook * **Trigger** : Triggered by fake brand GitHub URLs, `NvFsFilter` creation, or simultaneous termination of security products. * **Initial Verification** : Confirm ZIP download source, executing user, file hash, signature, and service registration time. * **Endpoint** : Preserve and remove drivers and persistence in Safe Mode or an external recovery environment. * **Authentication & Cloud**: From a known-clean endpoint, reset credentials stored in the affected browser and revoke all affected sessions and tokens. * **Subsequent Actions** : Track cryptocurrency transfers and unauthorized access to GitHub, email, and chat services. * **Containment** : Isolate the endpoint, block IOCs, block drivers, and update credentials. * **Judgment Categories** : Differentiate download, execution, driver operation, theft, and malicious use of stolen information. ## 11. Defense and Detection Ideas * **Single Event** : Detect `nvfsflt64.sys` deployment, the `NvFsFilter` service, and creation of the `\\.\Alinubx` device with high priority. * **Time-Series Correlation** : Correlate browser searches with large ZIP downloads, `vsdbg.exe` startup, UAC escalation, EDR termination, and external transmission. * **Hunting** : Search for PEs with abnormally large `.reloc`, DLLs adjacent to `vsdbg.exe`, and renamed drivers with identical signature families. * **Log Gaps** : Assuming EDR will be terminated, immediately forward DNS, Proxy, and Windows events off the endpoint. * **Priority Mitigations** : Enforce official distribution sources, apply application controls such as WDAC, and implement vulnerable driver mitigations. ## 12. Facts / Inference / Hypothesis ### Facts * Researchers identified the same distribution kit impersonating at least 40 companies. * Alinubx.sys carries a Microsoft Windows Hardware Compatibility Publisher signature and contains 145 built-in AV and EDR-related process names. * Rapuncel targets over 25 browsers and 30 cryptocurrency wallets. ### Inference * Combining signature families, services, IOCTLs, and parent-child processes provides better resilience against repackaging than relying solely on file names or hashes. ### Hypothesis No additional hypotheses. Unconfirmed items are listed in "Unknowns and Additional Investigation". ## 13. MITRE ATT&CK Mapping * **T1036 Masquerading** (Confidence: High): Masquerades as legitimate brands, Visual Studio debugger, and NVIDIA-style driver names. * **T1574.002 DLL Side-Loading** (Confidence: High): Loads malicious `vsdbg.dll` into `vsdbg.exe`. * **T1562.001 Impair Defenses** (Confidence: High): Terminates AV and EDR using a kernel driver. * **T1555 Credentials from Password Stores** (Confidence: High): Retrieves credentials from browsers and Windows Credential Manager. ## 14. Unknowns and Additional Investigation * Actual number of infections, affected regions, and scale of unauthorized usage after theft. * Timeline and target hashes for inclusion in Microsoft's driver block list. * Whether unused features present in Alinubx.sys were activated in other campaigns. ## 15. Impact on SOCs and Organizations Relying solely on GitHub hosting or Microsoft signatures as trust indicators can lead to missed detections. In environments where developers or administrators obtain tools through search engines, organizations should enforce official distribution sources and correlate signature issuers, expected file purposes, driver installation, and subsequent defense termination. ## 16. Summary by Role * **SOC** : Review `vsdbg.exe`, `NvFsFilter`, signed drivers, EDR termination, and C2 transmission chronologically. * **Administrators** : Restrict unofficial GitHub distributions, and implement WDAC, driver blocking, and external log forwarding. * **Users** : Obtain software from product official websites or official stores rather than GitHub pages found via search results.
dev.to
September 19, 2026 at 1:41 AM
Falsos repositórios no GitHub usam driver assinado para neutralizar 145 antivírus e roubar dados. 🚨

#dados #driver #github
Falsos repositórios no GitHub usam driver assinado para neutralizar 145 antivírus e roubar dados
Uma campanha maliciosa em curso está a utilizar repositórios otimizados para motores de busca no GitHub para se fazer passar por empresas de software conhecidas e distribuir um novo programa de roubo de dados designado Rapuncel. De acordo com uma investigação da LastPass e da Delphos Labs, os atacan
tugatech.com.pt
September 18, 2026 at 3:48 PM
偽のLastPass Authenticator GitHubリポジトリ、新型情報窃取マルウェア「Rapuncel」を拡散

 SEO最適化されたGitHubリポジトリを悪用し、有名ソフトウェア企業になりすまして、これまで確認されていなかった情報窃取マルウェア「Rapuncel」を拡散する新たなマルウェアキャンペーンが確認されました。 このキャンペーンを発見したLastPassとDelphos Labsによると、パスワード管理ソフ
偽のLastPass Authenticator GitHubリポジトリ、新型情報窃取マルウェア「Rapuncel」を拡散
 SEO最適化されたGitHubリポジトリを悪用し、有名ソフトウェア企業になりすまして、これまで確認されていなかった情報窃取マルウェア「Rapuncel」を拡散する新たなマルウェアキャンペーンが確認されました。 このキャンペーンを発見したLastPassとDelphos Labsによると、パスワード管理ソフ
blackhatnews.tokyo
September 18, 2026 at 3:32 PM
Hundreds kicked off Delphos Canal Days on Thursday with the 20th annual toast ahead of a weekend of rides, food, and games.
Delphos Canal Days kicks off with 20th Annual Toast
Hundreds gathered to raise a glass to another year of Canal Days, with plenty of rides, games, and food all weekend.
www.hometownstations.com
September 18, 2026 at 2:52 AM
arXiv📈🤖
Multitask Reinforcement Learning for Assisting Choice Model Specification
By Nova, Hess, Cranenburgh
September 17, 2026 at 6:19 AM