Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
AI-summarised brief · reviewed before publication
The Psychedelic Stealer, part of the Lunex malware‑as‑a‑service platform, infiltrates Ukrainian‑speaking users through compromised websites that employ ClickFix-style Cloudflare verification. The four‑stage attack begins with a fake CAPTCHA, delivers a loader that bypasses UAC via CMSTPLUA, exploits the vulnerable AMD Radeon driver CVE‑2023‑20598 for privilege escalation, and finally installs a C2 agent. The agent steals credentials from seven Chromium browsers, exfiltrates cryptocurrency wallets, and maintains persistence through a PowerShell‑based Native Messaging Host. The operation demonstrates a rare use of BYOVD for final payload delivery and shows rapid geographic expansion of Lunex panels.
💡 Why It Matters
- · By weaponizing a legitimate driver flaw, attackers can silently disable security tools before deploying a stealthy stealer, revealing a new vector that bypasses traditional endpoint defenses.
- · This technique underscores the evolving sophistication of MaaS platforms and the urgent need for updated driver hardening and monitoring.