Interestana
Home/News/Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
The Hacker News••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

The Lunex Stealer, a sophisticated malware-as-a-service (MaaS) platform, has been identified by cybersecurity firm Ontinue as the engine behind a targeted attack campaign aimed at Ukrainian-speaking users. This operation unfolds through a meticulously crafted four-stage attack chain, initiated via compromised Ukrainian websites. These websites employ a deceptive tactic, mimicking ClickFix-style Cloudflare verification checks, which present users with a seemingly legitimate, yet fake, CAPTCHA page. The primary objective of Lunex Stealer is the illicit acquisition of sensitive browser credentials. A particularly concerning capability of this malware is its ability to disable security monitoring tools, thereby operating with a significantly reduced risk of detection. This stealth is achieved through the exploitation of a legitimate AMD graphics driver. By abusing the functionalities of this trusted system component, Lunex Stealer can circumvent the watchful eyes of security software that would otherwise flag its malicious activities. This method of leveraging legitimate system drivers to mask malicious intent is a growing trend in advanced cyber threats, posing a substantial challenge to cybersecurity professionals tasked with detection and mitigation.

The distribution vector, which relies on the appearance of Cloudflare verification, is designed to exploit user trust and familiarity with common online security measures, thereby increasing the likelihood of successful user engagement. The fake CAPTCHA page acts as a potent social engineering tool, tricking unsuspecting users into downloading and executing the malware. Following this initial compromise, the malware systematically progresses through its predefined stages. The culmination of these stages involves the disabling of endpoint security monitoring and the subsequent exfiltration of stolen data. The primary target for data theft is browser credentials, which can encompass a wide range of sensitive information including usernames, passwords, and session cookies for various online services. The compromise of such credentials can have severe repercussions, potentially leading to unauthorized account takeovers, and subsequently, further financial losses or broader personal data breaches.

Ontinue's detailed analysis underscores the escalating sophistication and evolving nature of Malware-as-a-Service (MaaS) platforms. The specific technique of abusing a legitimate AMD driver by Lunex Stealer demonstrates a deep understanding of operating system internals and the intricate mechanisms of security software. While the current campaign appears to be geographically focused on Ukrainian users, the underlying MaaS platform may possess broader, more ambitious objectives. These findings serve as a stark reminder of the persistent and evolving threat posed by advanced malware. They also highlight the critical importance of implementing robust endpoint security solutions that are capable of detecting anomalous behavior, even when such behavior is masked by the abuse of legitimate system drivers.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next