AI Weekly Malaysia

Back to items Summaries

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

ID
28995
Status
summarized
Published
27 Sep 2026, 2:22 AM
Fetched
27 Sep 2026, 3:21 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/lunex-stealer-abuses-amd-driver-to.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
4.5
Created
27 Sep 2026, 3:22 AM
Tags
Audience
developers

What happened

The Lunex malware-as-a-service platform is delivering a four-stage chain that starts with a fake CAPTCHA ClickFix page on compromised Ukrainian websites and ends in Psychedelic Stealer. Ontinue researcher Rhys Downing reports that the LunexLoader stage bypasses Windows UAC via the CMSTPLUA COM object, then uses bring-your-own-vulnerable-driver (BYOVD) against the AMD Radeon Software driver PDFWKRNL.sys (CVE-2023-20598) to blind security processes while leaving them running, before the stealer extracts credentials from seven Chromium-based browsers, exfiltrates crypto wallets, and installs a PowerShell-based Native Messaging Host for persistent remote filesystem access. Arctic Wolf Labs had documented Psychedelic Stealer earlier the same week, tracing its iframe injection to compromised sites including a hair-treatment clinic, a scale-model manufacturer, a specialist bookseller, a psychological facility, a tool retailer, and an automotive retailer.

Why it matters

Two concrete things to check or decide. First, BYOVD is being used as a precursor to a commodity info stealer, not a ransomware payload, which means 'the process is still running' is no longer evidence that your endpoint security is working on a machine with an unpatched AMD Radeon driver (PDFWKRNL.sys / CVE-2023-20598) — worth verifying on Windows build machines and staff laptops, since EDR that can be blinded silently is the gap here. Second, the lure is a fake Cloudflare 'verify you are human' check that has victims paste a command into Windows Run; the current campaign targets Ukrainian-speaking users, but the ClickFix pattern is language-portable, so it is worth telling users never to paste commands from a web page into Run or PowerShell.

Discussion angle

BYOVD is trickling down from ransomware crews to commodity stealers — if an info stealer can switch off security tooling via a signed AMD driver, what does that change about how you'd detect a compromised Windows machine, given the malicious processes keep running and look alive?

Top