Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Lunex Stealer: A Sophisticated Malware Campaign Exploits AMD Driver Vulnerability to Steal Browser Credentials and Data




The Lunex Stealer is a sophisticated malware campaign that exploits the AMD driver vulnerability to steal browser credentials and data. The malware has been identified as part of a larger malware-as-a-service platform called Lunex, which has been distributed via compromised Ukrainian websites. The attack chain begins with a fake CAPTCHA page and culminates in the deployment of a fully-featured C2 agent, which extracts credentials and data from seven Chromium-based browsers. The infection uses bogus MSI installers delivered via ClickFix to trigger a series of actions, including delivering a loader dubbed LunexLoader that bypasses User Account Control (UAC) on Windows. The use of the BYOVD technique is significant, as it is rarely employed as a precursor to a final-stage payload like an information stealer. The Lunex Stealer's ability to compromise user data highlights the importance of staying informed and updated about the latest malware campaigns and vulnerabilities.



  • The Lunex Stealer malware is a sophisticated threat that can disable security monitoring and steal browser credentials and data.
  • The malware is part of a larger MaaS platform called Lunex, which uses compromised websites to distribute the malware.
  • The attack chain involves a fake CAPTCHA page, a fully-featured C2 agent, and the extraction of credentials and data from Chromium-based browsers.
  • The malware uses a vulnerable kernel-mode driver to escalate privileges and blind security-related processes.
  • The threat actor has compromised legitimate websites to serve the ClickFix lure, injecting an iframe element to distribute the malware.
  • The MaaS platform's feature set extends beyond credential theft to also enable brand impersonation and phishing.
  • The use of the BYOVD technique is significant, as it is rarely employed as a precursor to a final-stage payload like an information stealer.
  • The malware's ability to compromise user data highlights the importance of staying informed and updated about the latest malware campaigns and vulnerabilities.



  • The cybersecurity landscape has witnessed an influx of sophisticated malware campaigns in recent times, each designed to exploit specific vulnerabilities and compromise user data. One such campaign that has garnered significant attention in the threat intelligence community is the Lunex Stealer, a malware that has been identified as having the capability to disable security monitoring and steal browser credentials and data.

    The Lunex Stealer is a part of a larger malware-as-a-service (MaaS) platform called Lunex, which has been distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks. According to Ontinue, a threat researcher, the attack chain begins with a fake CAPTCHA page and culminates in the deployment of a fully-featured C2 agent, which extracts credentials and data from seven Chromium-based browsers, exfiltrates cryptocurrency wallets, and establishes persistent remote filesystem access through a PowerShell-based Native Messaging Host installed within the victim's browser.

    The infection makes use of bogus MSI installers delivered via ClickFix to trigger a series of actions, including delivering a loader dubbed LunexLoader that bypasses User Account Control (UAC) on Windows using the CMSTPLUA COM object, leveraging the bring your own vulnerable driver (BYOVD) attack for defense evasion, and finally downloading the stealer payload. The use of the BYOVD technique is significant, as it is rarely employed as a precursor to a final-stage payload like an information stealer. Lunex takes advantage of a vulnerable kernel-mode driver for AMD Radeon Software ("PDFWKRNL.sys"), which is susceptible to CVE-2023-20598, to escalate privileges and blind security-related processes while keeping them running.

    Psychedelic Stealer was first documented by Arctic Wolf Labs earlier this week, detailing the threat actor's modus operandi of compromising legitimate websites belonging to various businesses, including a hair-treatment clinic, a scale-model manufacturer, a specialist bookseller, a psychological facility, a tool retailer, and an automotive retailer to inject an iframe element designed to serve the ClickFix lure. The malware was found to be designed to use a legitimate but vulnerable driver to switch off security tools on the victim's machine, with those protections disabled, the information stealer is then deployed to take browser passwords, session cookies, and cryptocurrency wallet data.

    The earliest reference to Lunex in cybersecurity literature dates back to June 2026, when BlueTeamCoolTeam's Luke Wilkinson identified six active Lunex Stealer's command-and-control (C2) panels across the U.S., Finland, Germany, the Netherlands, and Ukraine. The growth in the number of panels identified across 13 countries, marking a major expansion from June 2026, points to a Russian-speaking developer or development team. These panels are hosted in Russia, the U.S., the U.K., the Netherlands, France, Germany, Turkey, and Bangladesh.

    One of the panels hosted in Turkey has been found to resolve to five phishing domains, including account-sams-club[.]com, teamwork-recover-password[.]com, namshi-uae[.]com, whatsappbusineses[.]com, and ibraq-perfumes[.]com. This indicates that the MaaS platform's feature set extends beyond credential theft to also enable brand impersonation and phishing. The BYOVD delivery chain, using PDB-guided kernel callback zeroing rather than process termination, represents a quieter approach to EDR neutralisation that leaves security products running but blind.

    "The use of the BYOVD technique is significant, not least because it's rarely employed as a precursor to a final-stage payload like an information stealer. Lunex takes advantage of a vulnerable kernel-mode driver for AMD Radeon Software ("PDFWKRNL.sys"), which is susceptible to CVE-2023-20598, to escalate privileges and blind security-related processes while keeping them running," Ontinue threat researcher Rhys Downing said.

    "Validated testing demonstrated that neither HVCI nor the current Microsoft Vulnerable Driver Blocklist prevents the specific PDFWKRNL.sys variant used in this chain from loading, a gap that persists despite the driver hash being catalogued in the LOLDrivers project since March 2026," Ontinue said.

    The Lunex Stealer's ability to compromise user data highlights the importance of staying informed and updated about the latest malware campaigns and vulnerabilities. It also underscores the need for robust cybersecurity measures, including the use of security tools and software that can detect and block malicious activity.

    The threat landscape continues to evolve, with new and sophisticated malware campaigns emerging regularly. Staying vigilant and informed is crucial in protecting oneself and one's organization from falling victim to these threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Lunex-Stealer-A-Sophisticated-Malware-Campaign-Exploits-AMD-Driver-Vulnerability-to-Steal-Browser-Credentials-and-Data-ehn.shtml

  • https://thehackernews.com/2026/09/lunex-stealer-abuses-amd-driver-to.html


  • Published: Sat Sep 26 14:43:47 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us