Lunex Stealer Exploits Vulnerable AMD Driver to Bypass Security and Steal Browser Credentials
Lunex Stealer exploits a vulnerable AMD driver (CVE-2023-20598) to bypass security monitoring and steal browser credentials, cryptocurrency wallets, and establish persistence on Windows systems. The malware uses a bring-your-own-vulnerable-driver (BYOVD) technique to escalate privileges while keeping security tools operational but ineffective.
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex.
The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users.
"The attack chain begins with a fake CAPTCHA page and
*** END OF TRANSMISSION ***