Lunex Stealer Hijacks AMD Driver to Disable Security Monitoring
Emily Davis ·
Listen to this article~4 min
A new malware campaign called Lunex Stealer is abusing a legitimate AMD driver to shut down security monitoring and swipe your saved browser credentials. Here's how it works.
You know that sinking feeling when your antivirus goes quiet and you're not sure why? That's exactly what a new malware campaign is counting on. A threat called Lunex Stealer has figured out a sneaky way to turn one of your computer's own drivers against you.
Here's what's happening, and why it matters even if you don't live in Ukraine.
### The Sneaky Delivery: Fake CAPTCHA Pages
Researchers at Ontinue recently uncovered a four-stage attack chain targeting Ukrainian-speaking users. It starts with compromised Ukrainian websites that pop up a fake Cloudflare verification check. You've seen these before, right? The little box that says "Verify you're human."
Except this one isn't real. It's part of a ClickFix-style trick that convinces you to run a malicious command yourself. Once you do, the malware known as Psychedelic Stealer slips onto your machine. And that's just the opening act.
### What Makes Lunex Different
Lunex isn't a one-off piece of malware. It's a full malware-as-a-service platform, meaning other criminals can rent it out and launch their own attacks. That's a big deal because it scales fast.
Here's the part that raised eyebrows: Lunex abuses a legitimate AMD driver to disable security monitoring. In plain English, it uses software your computer already trusts to quietly switch off the tools watching for bad behavior. No alarms. No warnings. Just silence.
> "The attack chain begins with a fake CAPTCHA page and ends with your browser credentials in someone else's hands."
### Why Browser Credentials Are the Real Prize
Once the security monitoring is out of the way, Lunex goes after saved passwords, cookies, and session tokens in your browser. Think about everything you've got stored there: email, banking, social media, work accounts. That's a treasure chest for attackers.
- Saved login credentials
- Active session cookies
- Autofill data including payment info
- Browser-stored tokens for two-factor bypass
If your browser is your digital front door, this malware walks right in and helps itself.
### The Four Stages, Simplified
- Stage 1: Fake CAPTCHA page on a compromised site
- Stage 2: User runs a malicious command (the ClickFix trick)
- Stage 3: Psychedelic Stealer installs and pulls in Lunex
- Stage 4: AMD driver abuse disables defenses, then credentials get stolen
### What You Can Actually Do About It
You don't need to be a security pro to protect yourself. A few smart habits go a long way.
- Never run commands from a website, no matter how official it looks
- Keep your browser and OS updated (yes, really)
- Use a password manager instead of browser-saved passwords
- Consider antidetect browser tools if you manage multiple accounts for work
- Watch for unexpected CAPTCHA prompts on sites you don't recognize
### The Bigger Picture
Malware-as-a-service platforms like Lunex are changing the game. You no longer need to be a skilled hacker to launch a serious attack. You just need a credit card and a grudge.
That's why staying informed matters. The more you know about how these campaigns work, the harder you are to fool. And honestly? That fake CAPTCHA trick is a perfect reminder: if something feels off, it probably is.
Stay sharp out there.