Published on September 27, 2026

Lunex Stealer Abuses Vulnerable AMD Driver to Disable Security Tools


Severity

Medium

Detail

A malware-as-a-service (MaaS) platform known as Lunex has been observed using a vulnerable AMD Radeon driver to weaken security protections before deploying an information-stealing malware called Psychedelic Stealer, also known as LunexStealer. The campaign targets Ukrainian-speaking users and uses a multi-stage infection chain that begins with fake CAPTCHA pages.

The attack combines ClickFix, UAC bypass, and Bring Your Own Vulnerable Driver (BYOVD) techniques to disable security monitoring and deploy the stealer. The vulnerable driver, PDFWKRNL.sys, is associated with CVE-2023-20598 and is used to escalate privileges and interfere with security-related processes while leaving them running.

How?

The attack begins with a fake CAPTCHA or Cloudflare verification page that tricks the victim into executing a malicious command. The command launches a bogus MSI installer, which starts the next stages of the infection.

The MSI package delivers LunexLoader, which attempts to bypass Windows User Account Control (UAC) through the CMSTPLUA COM object. It then loads the vulnerable AMD Radeon driver PDFWKRNL.sys to perform the BYOVD attack.

Rather than terminating security processes, the malware uses the vulnerable driver to interfere with security-related kernel callbacks, effectively leaving security products running while preventing them from properly observing malicious activity. Testing showed that both Hypervisor-Protected Code Integrity (HVCI) and Microsoft’s Vulnerable Driver Blocklist did not prevent the specific driver variant used in the attack from loading.

Once security monitoring has been weakened, Psychedelic Stealer is deployed. The malware targets credentials from Google Chrome, Microsoft Edge, Brave, Yandex Browser, Opera, Opera GX, and Vivaldi, along with data from multiple desktop and browser-based cryptocurrency wallets.

The malware also establishes persistence through a Registry Run key and a hidden scheduled task named psychedelicloveUtils. It installs a Chrome Native Messaging Host backed by a PowerShell script, allowing the attacker to interact with the victim’s file system even after the main stealer executable has been removed.

The Native Messaging component supports functions including drive and directory enumeration, file reading and writing, file downloads, and execution of programs. LunexStealer can also inject a malicious Chrome extension with broad permissions covering cookies, browsing history, bookmarks, tabs, storage, proxy settings, scripting, and web traffic.

The Lunex platform has expanded beyond a single operation, with 28 C2 panels identified across 13 countries. Researchers also found phishing domains associated with one of the panels, indicating that the platform can support activities beyond information theft, including brand impersonation and phishing.

Conclusion

The Lunex attack chain demonstrates how attackers can combine social engineering with legitimate but vulnerable drivers to bypass endpoint security before deploying an information stealer. By abusing PDFWKRNL.sys, the malware can interfere with security monitoring while continuing to operate normally on the affected system.

Source

https://thehackernews.com/2026/09/lunex-stealer-abuses-amd-driver-to.html