A new malware-as-a-service platform called Lunex is using a fake CAPTCHA and an AMD driver exploit to disable security and steal browser credentials. Learn how it works and how to protect yourself.
Imagine this: you click a Cloudflare verification check on a Ukrainian website, thinking it's just routine. But instead, you've just given a sneaky malware called Lunex the keys to your browser. That's the reality of a new malware-as-a-service (MaaS) platform that's making waves in the cybercrime world.
Security researchers at Ontinue recently uncovered a four-stage attack chain that targets Ukrainian-speaking users. The campaign, dubbed "Psychedelic Stealer," uses compromised websites and fake CAPTCHA pages to trick victims into downloading the malware. But what makes Lunex stand out is its clever abuse of an AMD driver to disable security monitoring and steal browser credentials.
### The Four-Stage Attack Chain
According to Ontinue, the attack unfolds in four distinct stages:
- **Initial Compromise:** Victims land on a compromised Ukrainian website that displays a fake Cloudflare verification check. This ClickFix-style tactic prompts users to download a file, which is actually the malware dropper.
- **Execution:** Once downloaded, the dropper runs a PowerShell script that fetches the main payload from a remote server.
- **Defense Evasion:** The payload then exploits a known vulnerability in an AMD driver to gain kernel-level privileges. This allows it to disable security tools like antivirus and endpoint detection, making it nearly invisible.
- **Credential Theft:** Finally, the malware extracts saved passwords, cookies, and other sensitive data from popular browsers like Chrome, Firefox, and Edge.
What's particularly alarming is how Lunex leverages a legitimate AMD driver to bypass security. "This is a classic example of living-off-the-land," says a researcher at Ontinue. "Attackers are using trusted components to avoid detection, and it's working."
### Why This Matters for You
If you're in the US, you might think this only affects Ukrainian users. But malware-as-a-service platforms like Lunex are sold to cybercriminals worldwide. The techniques used here can easily be adapted to target any region, including yours.
Moreover, the stolen credentials can be used for identity theft, financial fraud, or further attacks on your accounts. And because the malware disables security monitoring, you might not even know you're infected until it's too late.
### How to Protect Yourself
While the threat is serious, there are steps you can take to stay safe:
- **Keep your system updated:** Ensure your operating system, browser, and drivers are patched with the latest security updates. AMD has likely released a fix for the exploited driver, so update it ASAP.
- **Use a reputable antidetect browser:** Solutions like antidetect browsers can help mask your digital fingerprint and prevent tracking, but they're not a silver bullet. Combine them with other security measures.
- **Be wary of fake CAPTCHAs:** If a website asks you to complete a verification check that seems off—like requiring a download—close the tab immediately.
- **Enable multi-factor authentication (MFA):** Even if your credentials are stolen, MFA adds an extra layer of protection.
- **Run regular malware scans:** Use a trusted antivirus program and keep it updated.
### The Bigger Picture
The Lunex campaign highlights a growing trend: attackers are getting smarter, using legitimate tools and drivers to evade detection. As a user, your best defense is staying informed and proactive. Don't wait for a breach to take security seriously.
Remember, your digital privacy is worth protecting. Stay safe out there.