Lunex Stealer Abuses AMD Driver to Disable Security Monitoring
Headline by Prism · from 1 report
The Lunex malware-as-a-service platform uses a vulnerable AMD driver to disable security tools and steal user data.
The Hacker NewsThe brief
Written by software from the 1 report below.
- The Lunex malware platform distributes a stealer known as Psychedelic Stealer to compromise information from web browsers and cryptocurrency wallets.
- Attackers use compromised websites and fake browser verification pages to trick users into installing malicious loaders.
- A critical component of the attack is the exploitation of a vulnerable AMD Radeon kernel driver to blind security software.
- The platform has expanded rapidly since June 2026 and is used by various criminal groups for both credential theft and phishing.
What to watch next
- Potential updates to the Microsoft Vulnerable Driver Blocklist to include the specific PDFWKRNL.sys variant.
- The ongoing geographical expansion of Lunex command-and-control panels.
- Development of new phishing or brand impersonation tactics using the platform.
The points restate the reports; where one says why it matters, that is Prism's reading, not a reported fact.
Who said what
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Rhys Downing
threat researcher
3 quotes · 1 outlet
“The attack chain begins with a fake CAPTCHA page and culminates in the deployment of a fully-featured C2 agent”
In the article
…checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. " The attack chain begins with a fake CAPTCHA page and culminates in the deployment of a fully-featured C2 agent ," Ontinue threat researcher Rhys Downing said in a technical report. "The stealer extracts credentials and data from seven Chromium-based browsers, exfiltrates cryptocurrency wallets, and establishes persistent remote…
“'Psychedelic' is the name of the malware file that runs on victims' devices, while Lunex is the underlying platform being sold to multiple criminal groups, which is the reason for the name 'Lunex' and 'LunexStealer,'”
In the article
…and Ukraine. | LunexStealer (aka Psychedelic Stealer) C2 Panel | Source: BlueTeamCoolTeam | It's worth noting that both Psychedelic Stealer and LunexStealer refer to the same component of the MaaS platform. " 'Psychedelic' is the name of the malware file that runs on victims' devices, while Lunex is the underlying platform being sold to multiple criminal groups, which is the reason for the name 'Lunex' and 'LunexStealer,' " Downing explained. Upon execution, LunexStealer communicates with the Lunex panel at 193.178.159[.]128 over HTTP to facilitate comprehensive information theft - - Steal credentials from Google Chrome, Microsoft Edge,…
Coverage
1 outlet
All filed from India
NamedUkraine · Russia · United States · Finland · Germany · Netherlands · United Kingdom · France · Türkiye · Bangladesh · AMD · Microsoft · Arctic Wolf Labs · BlueTeamCoolTeam · Luke Wilkinson · Lunex · Ontinue · Psychedelic Stealer · Rhys Downing
The 1 report is listed beside the record.
Corrections and versions
A correction says what was wrong and why. Every earlier headline and brief of this record is kept.
Something wrong?
Say what, and it arrives with this record's address filled in. A correction is welcome.
Ask this story
Answers cite the 1 report above, or say they can't.