The Lunex Stealer, a malware-as-a-service (MaaS) operation, has been targeting Ukrainian users through compromised websites. This campaign leverages a sophisticated attack chain to bypass security measures and steal sensitive data from web browsers.
Multi-Stage Attack Process
According to Ontinue, the attack begins with a deceptive CAPTCHA page, ultimately leading to the installation of a command-and-control (C2) agent. The malware is capable of extracting credentials from several Chromium-based browsers and gaining access to cryptocurrency wallets. It maintains persistence through a PowerShell-based Native Messaging Host within the victim’s browser.
To deliver the malware, attackers use fake MSI installers that employ the ClickFix method, deploying a loader called LunexLoader. This loader bypasses User Account Control (UAC) on Windows and exploits a vulnerable AMD driver to evade security tools. The final payload is a stealer designed to exfiltrate browser credentials and cryptocurrency wallet data.
Technical Exploitation and Evasion Techniques
The use of the ‘bring your own vulnerable driver’ (BYOVD) technique is notable in this context. Lunex Stealer exploits an AMD Radeon Software driver to gain elevated privileges, disabling security monitoring without terminating processes. This method allows the stealer to operate undetected while extracting sensitive information.
Research by Arctic Wolf Labs highlights the malware’s infiltration methods, which include compromising legitimate websites to serve malicious iframes. These iframes deliver the malware, allowing it to disable security tools before stealing browser passwords and cryptocurrency data.
Command and Control Infrastructure
The Lunex Stealer communicates with its C2 infrastructure via HTTP to facilitate data theft. It targets browsers like Google Chrome, Microsoft Edge, and others, while also compromising cryptocurrency wallets such as Bitcoin Core and MetaMask. Persistence is achieved through registry keys and scheduled tasks, enabling ongoing data extraction.
Ontinue’s analysis reveals a network of 28 C2 panels across multiple countries, indicating the platform’s expansion. These panels, attributed to a Russian-speaking developer, suggest widespread use and distribution of the malware by multiple threat actors.
Broader Implications and Future Threats
The malware’s capabilities extend beyond data theft to include phishing and brand impersonation, as evidenced by phishing domains tied to the Turkish-hosted panels. This evolution underscores the growing threat posed by the Lunex platform and its capacity to adapt to different attack vectors.
The use of the BYOVD technique, particularly through the AMD driver, highlights gaps in current security measures. Despite being catalogued in the LOLDrivers project, the driver remains a viable vector for attacks, underscoring the need for enhanced cybersecurity defenses.
