Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Lunex Stealer Exploits AMD Driver for Credential Theft

Lunex Stealer Exploits AMD Driver for Credential Theft

Posted on September 26, 2026 By CWS

The Lunex Stealer, a malware-as-a-service (MaaS) operation, has been targeting Ukrainian users through compromised websites. This campaign leverages a sophisticated attack chain to bypass security measures and steal sensitive data from web browsers.

Multi-Stage Attack Process

According to Ontinue, the attack begins with a deceptive CAPTCHA page, ultimately leading to the installation of a command-and-control (C2) agent. The malware is capable of extracting credentials from several Chromium-based browsers and gaining access to cryptocurrency wallets. It maintains persistence through a PowerShell-based Native Messaging Host within the victim’s browser.

To deliver the malware, attackers use fake MSI installers that employ the ClickFix method, deploying a loader called LunexLoader. This loader bypasses User Account Control (UAC) on Windows and exploits a vulnerable AMD driver to evade security tools. The final payload is a stealer designed to exfiltrate browser credentials and cryptocurrency wallet data.

Technical Exploitation and Evasion Techniques

The use of the ‘bring your own vulnerable driver’ (BYOVD) technique is notable in this context. Lunex Stealer exploits an AMD Radeon Software driver to gain elevated privileges, disabling security monitoring without terminating processes. This method allows the stealer to operate undetected while extracting sensitive information.

Research by Arctic Wolf Labs highlights the malware’s infiltration methods, which include compromising legitimate websites to serve malicious iframes. These iframes deliver the malware, allowing it to disable security tools before stealing browser passwords and cryptocurrency data.

Command and Control Infrastructure

The Lunex Stealer communicates with its C2 infrastructure via HTTP to facilitate data theft. It targets browsers like Google Chrome, Microsoft Edge, and others, while also compromising cryptocurrency wallets such as Bitcoin Core and MetaMask. Persistence is achieved through registry keys and scheduled tasks, enabling ongoing data extraction.

Ontinue’s analysis reveals a network of 28 C2 panels across multiple countries, indicating the platform’s expansion. These panels, attributed to a Russian-speaking developer, suggest widespread use and distribution of the malware by multiple threat actors.

Broader Implications and Future Threats

The malware’s capabilities extend beyond data theft to include phishing and brand impersonation, as evidenced by phishing domains tied to the Turkish-hosted panels. This evolution underscores the growing threat posed by the Lunex platform and its capacity to adapt to different attack vectors.

The use of the BYOVD technique, particularly through the AMD driver, highlights gaps in current security measures. Despite being catalogued in the LOLDrivers project, the driver remains a viable vector for attacks, underscoring the need for enhanced cybersecurity defenses.

The Hacker News Tags:AMD Driver, browser credentials, BYOVD, C2 panel, credential theft, cryptocurrency wallets, cyber threat, Cybersecurity, Lunex Stealer, MaaS, Malware, Phishing, PowerShell, Psychedelic Stealer, security monitoring, UAC bypass

Post navigation

Previous Post: Local AI Model Evades EDR Detection with Modified Credential Dumper
Next Post: China and US to Create AI Safety Channel Amid Ongoing Talks

Related Posts

Why Your AI Security Tools Are Only as Strong as the Data You Feed Them Why Your AI Security Tools Are Only as Strong as the Data You Feed Them The Hacker News
New Fast16 Malware Uncovered: Cybersecurity Concerns Rise New Fast16 Malware Uncovered: Cybersecurity Concerns Rise The Hacker News
NGate Malware Exploits HandyPay App in Brazil for NFC Data Theft NGate Malware Exploits HandyPay App in Brazil for NFC Data Theft The Hacker News
Why CISOs Must Rethink Incident Remediation Why CISOs Must Rethink Incident Remediation The Hacker News
Microsoft Addresses High-Severity Windows Admin Center Flaw Microsoft Addresses High-Severity Windows Admin Center Flaw The Hacker News
North Korean Group Linked to Axios npm Attack North Korean Group Linked to Axios npm Attack The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles
  • Critical Vulnerability in Oracle PeopleSoft Exploited Globally

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles
  • Critical Vulnerability in Oracle PeopleSoft Exploited Globally

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark