Lunex Malware Exploits Vulnerable AMD Driver to Bypass Security Tools and Steal User Data

Views: 46 views

532/69 Monday, September 28, 2026

Cybersecurity researchers from Ontinue have disclosed a campaign involving Malware-as-a-Service known as Lunex, also referred to as Psychedelic Stealer, which is expanding its attacks against users across multiple countries. Initial findings show that threat actors are using fake websites that imitate Cloudflare verification pages to trick users into downloading the malware. A key concern is the use of advanced techniques specifically designed to disrupt security monitoring on victims’ devices, allowing the malware to covertly steal sensitive information from web browsers while making detection more difficult.

The attack begins by tricking victims into clicking a fake verification prompt that downloads an installer, which then launches a tool designed to bypass User Account Control (UAC). The malware subsequently uses a Bring Your Own Vulnerable Driver (BYOVD) technique targeting CVE-2023-20598 in an AMD Radeon driver to elevate privileges and interfere with security software, while the system interface may continue to indicate that protection is functioning normally. Once security defenses are disrupted, the malware begins stealing passwords, browser cookies, and cryptocurrency wallet data. It also deploys scripts capable of manipulating the file system and installing malicious browser extensions, allowing attackers to maintain access and monitor internet activity persistently even after the system is restarted.

Analysis found that the Lunex malware infrastructure is expanding rapidly and supports the creation of additional phishing websites for targeting users. Administrators and cybersecurity teams should therefore monitor the use of related driver files, particularly PDFWKRNL.sys, even though Microsoft has already implemented blocking measures, and should also investigate abnormal browser behavior. General users should exercise caution when encountering websites that ask them to click CAPTCHA-style verification prompts or download files to resolve unusual errors. If suspicious browser activity is detected, users should disconnect the device from the network and immediately perform an investigation using trusted security tools to reduce the risk of sensitive data theft.

Source: https://thehackernews.com/2026/09/lunex-stealer-abuses-amd-driver-to.html