How many of your employees could tell you the difference between a real GitHub repository and a convincing fake one? Most couldn’t, and that’s exactly what attackers are banking on.

The Rapuncel infostealer campaign is a masterclass in exploiting one simple fact: people trust brands more than they verify authenticity. Attackers aren’t trying to hack GitHub or compromise LastPass’s actual servers. They’re doing something far simpler, and far more effective. They’re creating fake versions of tools you already rely on and betting you won’t look too closely at where they came from.

Here’s what’s actually happening: criminals are setting up fake download pages and repositories that mimic popular developer tools and security software. When your team downloads what they think is a legitimate tool, they’re actually installing malware. One of the most active campaigns doing this right now (September 2026), Rapuncel, has managed to slip past 145 different security tools by using a Microsoft-signed driver that makes the malware look legitimate. The result is stolen credentials, compromised data, and no obvious sign anything went wrong.

The Setup: Trusting A Brand as Currency

Here’s the thing about trust in the digital world: it’s the ultimate currency. When you see a tool from a trusted company, hosted on a legitimate platform like GitHub, your brain does a quick calculation: “GitHub is legit. This company is legit. Therefore, this download is legit.” The logic seems sound, so you download it.

Attackers know this, which is why they’ve built an entire operation around it.

How It Actually Works

Let’s walk through what’s happening in detail:

Step 1: The Impersonation
Attackers set up repositories or download pages that look almost identical to the real thing. The URL might be slightly off, github.com vs. githxb.com, or a domain that sounds right but isn’t quite. They use legitimate-looking branding, screenshots, documentation, and if you’re in a hurry (and let’s be honest, most of us are), you might not notice.

Step 2: The Payload
Inside these fake downloads is malware, in this case, an infostealer that does exactly what its name suggests: it steals information. Your credentials, your browser session data, your files, it’s designed to be quiet about it, sitting in the background while you go about your day.

Step 3: The Bypass
Here’s where it gets interesting. The malware uses a Microsoft-signed driver, meaning it has a digital signature that says, “Hey, Microsoft checked this, it’s legit.” This legitimacy allows it to slip past 145 different security tools that might otherwise catch it, since those tools see the Microsoft signature and think, “Well, Microsoft wouldn’t sign something malicious,” and let it through.

It’s trust, weaponized.

Why This Matters to You

If you’re a small business owner or manager, here’s why you should care: your team members are targets. Someone on your payroll, looking for a tool to do their job better or faster, finds what looks like exactly what they need, downloads it, installs it, and suddenly your business data is walking out the door.

But here’s the thing, this isn’t about being careless or uninformed. This is about how sophisticated social engineering has become. These campaigns don’t rely on you being dumb. They rely on you being human: overloaded, busy, trusting, and moving fast.

The Real Vulnerability Isn’t Technical

The reason Rapuncel bypassed so many security tools isn’t because those tools are broken. It’s because the real vulnerability lives between the keyboard and the chair. It’s you and me, making quick decisions based on trust.

Security tools are designed to catch malicious code, but they can’t catch a decision made by a human who believes they’re downloading from a legitimate source. That’s not a technical problem you can patch, that’s a people problem.

What Actually Helps

So what do you do? A few simple things, actually:

Verify the source directly. If someone recommends a tool, don’t just follow a link they send. Go to the company’s official website and download from there, one extra step, that’s it.

Check the URL carefully. I know it sounds tedious, but when you’re about to download something, take five seconds to make sure the URL is exactly what you expect. Not close, exactly.

Be skeptical of urgency. If you suddenly need a tool “right now” because something’s broken, that’s the moment to slow down, not speed up. Get a colleague to verify the source with you.

Communicate this with your team. Your employees don’t need to become security experts. They just need to know that if they’re downloading something, they should verify it’s real before they install it. Make it a norm, not a burden.

Use official channels. If a tool offers installation through your company’s standard software management system or through an official app store, use that instead of downloading directly.

The Bigger Picture

Campaigns like Rapuncel work because they exploit something fundamental about how we operate as humans, we trust institutions, brands, and platforms. That’s not a character flaw,  it’s how society functions. We can’t verify everything from first principles every single time.

But right now, with infostealer campaigns actively targeting businesses, that baseline trust needs a small upgrade: a habit of verification before installation.

You don’t need to become paranoid, you just need to pause for a second before you click and actually look at what you’re clicking on.

With all the security tools our businesses have deployed these days, us, the people, become the weak link in the chain. That question at the beginning, the one about whether your employees could spot a fake, that’s the real measure of your security posture right now.

Posted by Nathan R on September 25, 2026