Lunex Stealer Weaponizes AMD Driver to Bypass Security and Swipe Browser Credentials

·
Listen to this article~4 min
Lunex Stealer Weaponizes AMD Driver to Bypass Security and Swipe Browser Credentials

Lunex Stealer exploits an AMD driver to disable security monitoring and steal browser credentials. Learn how this malware works and how to protect yourself.

### The New Threat Bypassing Your Security You know that uneasy feeling when your antivirus says everything's fine, but something just feels off? That's exactly the nightmare Lunex Stealer is creating for security teams right now. This malware doesn't just steal your data. It disables the very tools designed to catch it, all by exploiting a trusted AMD driver. According to new research from Ontinue, Lunex Stealer is part of a broader malware-as-a-service platform called Lunex. It's been spreading through compromised Ukrainian websites, using fake Cloudflare verification checks to trick visitors into running malicious code. The attack chain is a four-stage process that starts with a simple-looking CAPTCHA page. ### How the Attack Unfolds The first stage is almost boringly familiar. You land on a compromised site, and a fake Cloudflare "Verify you are human" prompt appears. You click it, and instead of a simple check, you're instructed to paste a command into a Run dialog or terminal. That single action kicks off the entire infection. Once executed, the malware downloads a loader that uses the AMD driver to gain kernel-level access. That's the key move. By abusing a legitimate, signed driver, the malware can disable security monitoring tools without raising red flags. It's like a burglar who has a copy of your house key, so the alarm never goes off. From there, Lunex Stealer goes after browser credentials. It extracts saved passwords, cookies, and session tokens from Chrome, Firefox, and other browsers. That means even if you use unique passwords, your active sessions can be hijacked. ### Why This Matters for Everyday Users You might think, "I'm not in Ukraine, so I'm safe." But that's not how these campaigns work. The infrastructure behind Lunex is rented out to other cybercriminals. The same tactics can easily be repurposed for English-speaking targets in the US and elsewhere. > "The most dangerous malware is the kind that makes you think you're not infected." — Michael Miller, Lead Antidetect Browser Strategist That quote sums it up. If your security tools are blinded, you won't know you've been compromised until it's too late. ### Protecting Yourself Without Panic First, don't click on CAPTCHA prompts that ask you to run commands. Real CAPTCHAs never do that. Second, keep your browser and OS updated. Third, consider using an antidetect browser for sensitive browsing. These browsers isolate your sessions and make it harder for malware to fingerprint your system. Here's what you can do right now: - Never paste commands from a website into your terminal or Run dialog. - Use a password manager with built-in phishing protection. - Enable two-factor authentication everywhere, preferably with an app or hardware key. - Regularly review your browser's saved passwords and remove ones you don't need. - Keep an eye on security news for emerging threats like Lunex. ### The Bigger Picture Lunex Stealer shows how creative attackers can be. They're not just writing new malware; they're finding ways to turn trusted components against us. As long as there's money in stolen credentials, these techniques will keep evolving. Your best defense is awareness and layered security. Don't rely on a single tool. Stay skeptical, stay updated, and stay safe.