Home » Hackers Use Microsoft-Signed Driver to Disable 145 Security Tools and Steal Passwords
| Indicator Type | Indicator |
| Malicious driver SHA-256 | 611b3ba687b7f46319a19609605ddfe5225e6d85277d8e923eea3fdb6f7b5b61 |
| Rapuncel payload SHA-256 | aefbc6e04320e9a0e80f2323f8a897c4fdb222a37b0b87d76e850109decbfadd |
| Primary payload server | albinofennel[.]com |
| Secondary payload server | hanselarinmusky[.]com |
| Fake GitHub repository | github[.]com/LastPass-Authenticator |
| Fake GitHub Pages portal | lastpass-authenticator[.]github[.]io |
| Exfiltration IP | 2.26.126[.]50 |
| Malicious driver path | C:\Windows\System32\drivers\nvfsflt64.sys |
| Driver service | NvFsFilter |
| Driver interface | \\.\Alinubx |
| Rootkit helper | ProtectR3.dll |
| Malicious loader | vsdbg.dll |
| Credential-stealing artifact | browser_decryption.log |
| Related signing identity | Henan Dafeng Software Co., Ltd. |
Copyright @Seceon Inc 2026. All Rights Reserved.