Lunex Stealer Uses AMD Driver to Blind Security Tools

Lunex Stealer Uses AMD Driver to Blind Security Tools

Ontinue researchers reveal Lunex malware abuses a vulnerable AMD driver to disable EDR protection and steal browser credentials via ClickFix lures.

A sophisticated malware operation known as Lunex is currently targeting users by exploiting a vulnerability in an AMD graphics driver to neutralize endpoint detection and response (EDR) security tools. According to a technical report by Ontinue threat researcher Rhys Downing, the campaign utilizes a four-stage attack chain designed specifically to compromise Ukrainian-speaking users. The infection begins with compromised websites injecting a fake CAPTCHA page that employs a technique called ClickFix. This method tricks users into manually executing malicious scripts by presenting them with a deceptive Cloudflare verification check. Once the user interacts with the lure, they inadvertently download a loader named LunexLoader.

The LunexLoader is engineered to bypass Windows User Account Control (UAC) protections using the CMSTPLUA COM object. More critically, it leverages a Bring Your Own Vulnerable Driver (BYOVD) attack to escalate privileges. The malware targets the PDFWKRNL.sys kernel-mode driver, which is part of AMD Radeon Software and is susceptible to CVE-2023-20598. By abusing this driver, the stealer can execute code with high-level system access. Crucially, this does not terminate security processes but instead blinds them. Ontinue describes this as PDB-guided kernel callback zeroing, a technique that leaves security products running but unable to monitor or detect further malicious activity. Validated testing confirmed that neither Hypervisor-Protected Code Integrity (HVCI) nor Microsoft’s current Vulnerable Driver Blocklist prevents this specific variant of the AMD driver from loading, despite the driver hash being listed in the LOLDrivers project since March 2026.

Once security monitoring is disabled, the final payload, referred to as Psychedelic Stealer, is deployed. This component communicates with a command-and-control (C2) server at 193.178.159[.]128 over HTTP to exfiltrate data. The stealer extracts credentials and session cookies from seven Chromium-based browsers: Google Chrome, Microsoft Edge, Brave, Yandex Browser, Opera, Opera GX, and Vivaldi. It also enumerates and steals data from five desktop cryptocurrency wallets including Bitcoin Core, Litecoin, Exodus, Atomic Wallet, and Electrum, as well as four browser extension wallets such as MetaMask, OKX Wallet, and SafePal Wallet.

Persistence is maintained through multiple vectors. The malware registers a Registry Run key and creates a hidden scheduled task named psychedelicloveUtils. Additionally, it installs a PowerShell-based Native Messaging Host (NMH) within the victim's browser. This host is backed by a 13,200-byte PowerShell script embedded in the .rdata section of the binary. Operating within the Chrome process context, the NMH survives binary deletion, system reboots, and browser restarts. It grants the attacker six file system actions: listing drives and directories, reading files up to 524 MB, writing arbitrary data, downloading files, and executing programs. The stealer also injects a malicious Chrome extension by manipulating Secure Preferences, granting extensive permissions for cookies, history, bookmarks, tabs, storage, proxy settings, scripting, and all HTTP/HTTPS URLs.

The Lunex platform appears to be a Malware-as-a-Service (MaaS) solution sold to various criminal groups. While Arctic Wolf Labs first documented the distribution method involving compromised legitimate websites in Ukraine, BlueTeamCoolTeam identified active C2 panels in June 2026 across the U.S., Finland, Germany, the Netherlands, and Ukraine. As of the latest analysis, 28 unique panels have been identified across 13 countries, including Russia, the U.K., France, Turkey, and Bangladesh. One panel hosted in Turkey resolves to phishing domains impersonating brands like Sams Club and WhatsApp Business, indicating the platform supports both credential theft and brand impersonation. The rapid expansion suggests active development by a Russian-speaking team.

For website owners and IT teams, this incident highlights the critical risk of supply-chain compromises on legitimate sites and the effectiveness of BYOVD attacks in evading modern defenses. The use of ClickFix on trusted domains demonstrates how social engineering can bypass perimeter security. Users are advised to remain skeptical of manual execution prompts required for CAPTCHA verifications.

If your infrastructure relies on managed hosting or secure DNS resolution, AEU-I provides security-first IT consulting and infrastructure services to help you assess and harden your environment against these types of advanced persistent threats and supply-chain risks.

So schützen Sie sich

  1. Never click buttons that ask you to copy and paste commands or manually run scripts to verify you are human, as this is often a trick to install malware.
  2. Keep your computer operating system and graphics drivers updated to the latest versions provided by your hardware manufacturer to reduce known vulnerabilities.
  3. Use strong, unique passwords for all your accounts and enable two-factor authentication so that stolen browser passwords alone cannot grant access to your accounts.
  4. Install reputable antivirus software and keep it updated, understanding that while it may not stop every advanced exploit, it adds a layer of defense against common threats.

Schwachstellen & Lösungen

Begriffe Erklärt

  • ClickFix A social engineering technique where attackers trick users into manually copying and pasting commands or running scripts to appear to complete a verification step.
  • BYOVD Bring Your Own Vulnerable Driver, an attack method that uses a legitimate but flawed driver installed on the system to gain unauthorized high-level access.
  • EDR Endpoint Detection and Response, security software that monitors computers and servers to identify and stop cyber threats in real time.
  • Native Messaging Host A program that allows a web browser to communicate directly with applications on the local computer, which attackers can abuse to maintain control.
  • HVCI Hypervisor-Protected Code Integrity, a Windows security feature that helps prevent malicious code from running by validating code signatures before execution.
  • LOLDrivers A public database that lists legitimate drivers that have known vulnerabilities and can be abused by attackers to bypass security controls.

Verwandte AEU-Dienste

  • AEU-I IT- und Sicherheitsberatung