Delphos Labs reposted this
New threat intel. The LastPass TIME team and Delphos identified and disrupted a multi-stage malware delivery campaign impersonating at least 40 companies on GitHub. The payload delivered a Microsoft-attested kernel driver that terminated 145 antivirus and EDR processes from kernel mode. It scored 0 out of 72 on VirusTotal as of August 20, unchanged since July 2025. Thanks to Mike Kosak and Stephanie (Keinz) Schneider on the LastPass TIME team for working this one with us. The driver is a renamed copy of CcProtect.sys, which LOLDrivers already catalogues as a BYOVD process killer, with public proof-of-concept code. Same product string, version, and submitter. The operators changed the filename to Alinubx.sys. That was the evasion. Detections keyed to the known name did not match, and renaming a file changes its bytes, so the SHA256 moved with it. A blocklist of known bad hashes does not have this one. From there it opens each target process with KernelMode access, which skips the user-mode access check and defeats Protected Process Light without touching EPROCESS bits. There is no exploit here. The process-kill interface is product functionality, exposed by a host-defense driver that Windows trusts. Same driver, same version, same submitter, one new filename. That was enough. Joint writeup with the LastPass TIME team, on the Delphos Labs blog. Hashes, hunt queries, the full CcProtect comparison, and the MSRC timeline are in the post. https://lnkd.in/ePTJDXPA