VMTech
Discuss a project →

Lunex Stealer Uses AMD Driver to Evade Endpoint Monitoring

Lunex Stealer Uses AMD Driver to Evade Endpoint Monitoring

Researchers at Ontinue have detailed a Lunex malware-as-a-service campaign that uses a vulnerable AMD Radeon Software kernel driver, PDFWKRNL.sys, to weaken endpoint monitoring before deploying an information stealer. The campaign, aimed at Ukrainian-speaking users, begins with compromised websites and ClickFix-style fake Cloudflare verification pages, then delivers bogus MSI installers.

The final payload, also known as Psychedelic Stealer, steals credentials and data from seven Chromium-based browsers: Google Chrome, Microsoft Edge, Brave, Yandex Browser, Opera, Opera GX and Vivaldi. It also targets desktop and browser-extension cryptocurrency wallets, while establishing persistent access to the victim's file system through a PowerShell-based Chrome Native Messaging Host.

A four-stage chain built around driver abuse

Ontinue describes the operation as a four-stage attack chain. A fake CAPTCHA page leads victims to run a malicious installer, which deploys LunexLoader. The loader is designed to bypass Windows User Account Control through the CMSTPLUA COM object, use a bring-your-own-vulnerable-driver technique for defence evasion, and download the stealer.

The driver component is significant because the chain uses PDFWKRNL.sys, a vulnerable AMD Radeon Software driver affected by CVE-2023-20598. Lunex uses it to elevate privileges and disable security-related monitoring while leaving the associated processes running. Ontinue said this approach uses PDB-guided kernel callback zeroing rather than terminating processes, allowing security products to appear active while becoming unable to observe malicious activity.

Validated testing by Ontinue found that neither Hypervisor-Protected Code Integrity nor the current Microsoft Vulnerable Driver Blocklist stopped the specific PDFWKRNL.sys variant from loading. The driver hash had been catalogued by the LOLDrivers project since March 2026.

Credential theft and browser-resident persistence

After execution, LunexStealer communicates over HTTP with a Lunex panel at 193.178.159[.]128. It can extract browser passwords and session cookies, enumerate five desktop wallets—Bitcoin Core, Litecoin, Exodus, Atomic Wallet and Electrum—and collect data from MetaMask, MetaMask Legacy, OKX Wallet and SafePal Wallet browser extensions.

The malware also creates persistence with a Registry Run key and a hidden scheduled task named psychedelicloveUtils. Its Chrome Native Messaging Host is backed by a 13,200-byte PowerShell script embedded in the binary's .rdata section. Operating in Chrome's process context, the host can survive deletion of the stealer binary, reboots and browser restarts.

That script supports drive enumeration, directory listing, arbitrary file reads in 512 KB chunks for files up to 524 MB, file writes, downloads and program execution. Lunex additionally manipulates Chrome Secure Preferences to inject an extension with permissions covering cookies, history, bookmarks, tabs, storage, proxy, scripting, declarativeNetRequest and all HTTP and HTTPS URLs.

Expanding platform infrastructure

Lunex is the underlying platform sold to criminal groups, while Psychedelic is the malware file name used on victim devices. BlueTeamCoolTeam first identified six active Lunex command-and-control panels in June 2026. Ontinue has now identified 28 unique panels across 13 countries, with infrastructure hosted in Russia, the United States, the United Kingdom, the Netherlands, France, Germany, Turkey and Bangladesh.

One Turkey-hosted panel resolved to five phishing domains, indicating that the platform can support brand impersonation and phishing in addition to credential theft. For businesses, the practical implication is to assess ClickFix exposure, browser credential protection and vulnerable-driver controls together, since an endpoint product that remains visible and running may not necessarily retain effective monitoring.

#cybersecurity#malware#endpointsecurity#browsersecurity
Open analytics
On the site 19 views
min read 4 26.09.2026
On Instagram 2 views
On Instagram 1 reach
Instagram

Lunex Stealer Uses AMD Driver to Evade Endpoint Monitoring

Open the post on Instagram ↗