Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
Executive Summary
Lunex Stealer, a malware-as-a-service (MaaS) tool, targets Ukrainian-speaking users through a four‑stage attack chain. It begins with a fake CAPTCHA page that redirects to a ClickFix‑style Cloudflare verification, then drops a malicious AMD driver to disable security monitoring, and finally steals browser credentials. The malware is distributed via compromised Ukrainian websites and leverages the driver to evade detection.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-26T18:22:52+00:00 - Category: threat-intel
Original Description: The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAPTCHA page and
"To give hope to someone occurs when you teach them how to use the tools to do it for themselves."
— Byron Pulsifer