Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
- ID
- 28995
- Status
- summarized
- Published
- 27 Sep 2026, 2:22 AM
- Fetched
- 27 Sep 2026, 3:21 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/lunex-stealer-abuses-amd-driver-to.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 4.5
- Created
- 27 Sep 2026, 3:22 AM
- Tags
- Audience
- developers
What happened
The Lunex malware-as-a-service platform is delivering a four-stage chain that starts with a fake CAPTCHA ClickFix page on compromised Ukrainian websites and ends in Psychedelic Stealer. Ontinue researcher Rhys Downing reports that the LunexLoader stage bypasses Windows UAC via the CMSTPLUA COM object, then uses bring-your-own-vulnerable-driver (BYOVD) against the AMD Radeon Software driver PDFWKRNL.sys (CVE-2023-20598) to blind security processes while leaving them running, before the stealer extracts credentials from seven Chromium-based browsers, exfiltrates crypto wallets, and installs a PowerShell-based Native Messaging Host for persistent remote filesystem access. Arctic Wolf Labs had documented Psychedelic Stealer earlier the same week, tracing its iframe injection to compromised sites including a hair-treatment clinic, a scale-model manufacturer, a specialist bookseller, a psychological facility, a tool retailer, and an automotive retailer.
Why it matters
Two concrete things to check or decide. First, BYOVD is being used as a precursor to a commodity info stealer, not a ransomware payload, which means 'the process is still running' is no longer evidence that your endpoint security is working on a machine with an unpatched AMD Radeon driver (PDFWKRNL.sys / CVE-2023-20598) — worth verifying on Windows build machines and staff laptops, since EDR that can be blinded silently is the gap here. Second, the lure is a fake Cloudflare 'verify you are human' check that has victims paste a command into Windows Run; the current campaign targets Ukrainian-speaking users, but the ClickFix pattern is language-portable, so it is worth telling users never to paste commands from a web page into Run or PowerShell.
Discussion angle
BYOVD is trickling down from ransomware crews to commodity stealers — if an info stealer can switch off security tooling via a signed AMD driver, what does that change about how you'd detect a compromised Windows machine, given the malicious processes keep running and look alive?