Last seven days
- First activity
- Sep 22, 2026
- Last activity
- Sep 22, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
Rapuncel is a Windows information stealer distributed in a search-engine-optimization poisoning campaign that impersonates software vendors, including LastPass, through fraudulent GitHub repositories and download pages.
Profile source: Mallory opens in a new tabRapuncel
Rapuncel is a Windows information stealer distributed in a search-engine-optimization poisoning campaign that impersonates software vendors, including LastPass, through fraudulent GitHub repositories and download pages. Victims receive inflated ZIP archives containing a disguised installer that uses DLL side-loading to execute the payload. The campaign deploys a Microsoft-attested kernel driver derived from the CnCrypt/CcProtect driver line to terminate antivirus and EDR processes, including protected processes, before running the stealer. Rapuncel obtains elevated privileges, establishes auto-start Windows service persistence, and repeatedly suppresses restarted security tools. It steals saved browser credentials, cryptocurrency-wallet data, Discord tokens, Steam and Telegram session data, Windows Credential Manager contents, selected credential- and wallet-related documents, screenshots, and host information. It bypasses Chrome and Edge app-bound encryption through browser-process injection and use of browser decryption services, then compresses and exfiltrates collected data. The loader has been assessed as likely built with, or closely derived from, Cruciferra PUROSANGUE. Rapuncel has moderate-confidence behavioral and delivery-chain links to the BoryptGrab ecosystem, but is not assessed as an identical build.
C2 tracking
Derp observations, rolling seven-day window
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.