HomeSecurityLunex Stealer: New malware exploits AMD driver

Lunex Stealer: New malware exploits AMD driver

Lunex Stealer exploits a vulnerable AMD driver to limit the visibility of security tools and steal passwords from browsers. The new campaign starts from compromised Ukrainian websites and uses a fake Cloudflare audit, in an attack chain that primarily targets Ukrainian-speaking users.

The findings come from the Ontinue Cyber ​​Defense Centre and were presented in an analysis by The Hacker News. The researchers link Psychedelic Stealer to the Malware-as-a-Service platform Lunex, which appears to be available to more than one criminal group.

The campaign is not based on a single malicious file. Attackers insert hidden frames into legitimate pages and display a window that mimics Cloudflare verification. The message asks the visitor to run a command in Windows, turning a familiar security procedure into a trap.

The ClickFix technique has been used in other attacks, but here it is combined with privilege escalation and kernel driver abuse. This increases the risk for users who believe they are simply completing an access check.

See also: ClickFix attacks distribute new ChainScript RAT

Lunex Stealer and fake ClickFix verification on compromised website

How does Lunex Stealer work?

The chain begins with a fake CAPTCHA check and continues with an MSI installer delivered via ClickFix. LunexLoader then attempts to bypass Windows User Account Control via the COM object CMSTPLUA in order to gain the necessary permissions for the next stages.

The special feature is the Bring Your Own Vulnerable Driver (BYOVD) technique. The loader loads PDFWKRNL.sys, a driver associated with AMD Radeon Software and has been associated with CVE-2023-20598. The vulnerability allows kernel-level actions, which the malware uses to reduce the effectiveness of detection mechanisms.

According to technical analysis, the protection products' processes are not necessarily terminated. Instead, the chain nullifies selected kernel callbacks so that the tools continue to appear active, while losing some of their visibility. This approach can delay detection on systems where strict driver control is not applied.

Lunex Stealer exploits vulnerable AMD driver CVE-2023-20598

What data is the malware looking for?

After defeating the defenses, the final payload collects passwords, session cookies, and cryptocurrency wallet data. The analysis reports support for seven Chromium browsers, while a PowerShell-based Native Messaging Host allows the malware to communicate with the browser and maintain access across reboots.

The sample can also install a malicious extension by modifying Chrome settings. The permissions it requests include cookies, history, bookmarks, tabs, cached data, proxy management, and execution on web pages. Thus, the theft is not limited to a single code but extends to the victim's browsing environment.

Ontinue says it identified six active control centers in June, with a total of 28 unique panels across 13 countries. It also assesses that a Russian-speaking developer or development team is behind the platform, but this is not a definitive attribution of the specific campaign. The relevant research entry appears in Ontinue’s resource center as “Lunex Unmasked.”

See also: WeaselBiscuit Stealer is distributed via malicious npm packages

Lunex Stealer steals browser passwords and cryptocurrency data

How can users be protected?

Users should not execute commands displayed on CAPTCHA pages or pop-ups, even if the page appears legitimate. Windows administrators should check the version of AMD Radeon Software, install available updates, and enable policies that restrict the loading of unapproved drivers.

The SecNews technical team also recommends resetting passwords from a clean device, canceling active sessions, and checking Chrome extensions after a suspicious incident. Monitoring installed drivers, unusual PowerShell actions, and changes to browser settings can help detect the attack early.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The incident shows that a fake verification and an old, vulnerable driver can work together, bypassing successive layers of protection. The Lunex Stealer reminds us that protection should cover not only the final file, but also drivers and browser settings. Organizations need to combine updates, permission restrictions, and change logging in browsers, rather than relying on a single defense. Avoiding ClickFix commands, timely software updates, and strict driver control remain the most immediate risk mitigation measures.

See also: MacSync distributes payloads via public iCloud calendars

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS