This AMD Driver Exploit Is Quietly Draining Browser Vaults
Emily Davis ·
Listen to this article~4 min
A malware-as-a-service platform called Lunex is using a compromised AMD driver to disable security tools and steal browser credentials. Here's how the attack works and what you can do.
You know that little padlock icon in your browser? The one that makes you feel safe when you're logging into your bank or checking your email? A new malware campaign is using it as a smokescreen, and it's doing it through a vulnerability that most people didn't see coming.
Security researchers at Ontinue have uncovered a nasty piece of work called Lunex. It's a malware-as-a-service platform, which is exactly what it sounds like: a subscription-based toolkit that lets even low-skill cybercriminals launch sophisticated attacks. And the delivery method? Compromised Ukrainian websites serving up fake Cloudflare verification checks.
### The Four-Stage Trap
Here's how it unfolds. You land on a compromised site, and a CAPTCHA-style box pops up asking you to verify you're human. It looks legitimate. It feels routine. But that fake CAPTCHA is actually a ClickFix lure, a social engineering trick designed to get you to paste malicious code into your clipboard or run a command without realizing it.
Once that happens, the attack chain moves through four distinct stages:
- **Initial access** via the fake verification page
- **Payload delivery** that installs the Psychedelic Stealer
- **Defense evasion** using a vulnerable AMD driver to disable security monitoring
- **Credential harvesting** that targets saved browser passwords, cookies, and session tokens
The AMD driver angle is what makes this particularly concerning. By exploiting a known vulnerability in the driver, the malware can effectively blind your antivirus and endpoint protection tools. It's like someone cutting the security cameras before robbing the bank.
### Why Browser Credentials Are the Real Prize
Think about everything stored in your browser right now. Passwords, yes, but also autofill data, credit card numbers, and active session cookies that let attackers bypass two-factor authentication entirely. For professionals who manage multiple accounts, client logins, or e-commerce platforms, this isn't just an inconvenience. It's a direct threat to your livelihood.
> "The most dangerous malware doesn't announce itself. It sits quietly, learns your habits, and strikes when you least expect it."
The Ukrainian targeting makes sense from a geopolitical standpoint, but the underlying MaaS model means these tools will inevitably spread. Cybercriminals share, sell, and iterate. What starts as a regional campaign rarely stays that way.
### Protecting Yourself Without Going Off the Grid
You don't need to abandon the internet. You just need to be smarter about how you use it.
- **Never trust a CAPTCHA that asks you to run commands or paste code.** Legitimate verification tools don't work that way.
- **Keep your browser and drivers updated.** That AMD vulnerability likely has a patch. Apply it.
- **Use a password manager instead of browser storage.** It adds a layer of encryption that saved passwords in Chrome or Firefox simply don't have.
- **Consider antidetect browser solutions** if you're managing multiple profiles. They isolate sessions and reduce the attack surface significantly.
- **Enable endpoint detection that watches for driver-level tampering.** Standard antivirus often misses this.
The reality is that threats like Lunex aren't going away. They're getting more creative, more targeted, and more accessible to anyone with a grudge and a credit card. Your best defense is staying informed and layered up.
Because the next fake CAPTCHA you see might not be checking if you're human. It might be checking if you're vulnerable.