Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
thehackernews.com Sep 26, 2026

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

AI-summarised brief · reviewed before publication

The Psychedelic Stealer, part of the Lunex malware‑as‑a‑service platform, infiltrates Ukrainian‑speaking users through compromised websites that employ ClickFix-style Cloudflare verification. The four‑stage attack begins with a fake CAPTCHA, delivers a loader that bypasses UAC via CMSTPLUA, exploits the vulnerable AMD Radeon driver CVE‑2023‑20598 for privilege escalation, and finally installs a C2 agent. The agent steals credentials from seven Chromium browsers, exfiltrates cryptocurrency wallets, and maintains persistence through a PowerShell‑based Native Messaging Host. The operation demonstrates a rare use of BYOVD for final payload delivery and shows rapid geographic expansion of Lunex panels.

💡 Why It Matters

  • · By weaponizing a legitimate driver flaw, attackers can silently disable security tools before deploying a stealthy stealer, revealing a new vector that bypasses traditional endpoint defenses.
  • · This technique underscores the evolving sophistication of MaaS platforms and the urgent need for updated driver hardening and monitoring.