hacker-news · Crawled Sep 26, 2026

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

6 IoCs
Read original article ↗

AI Summary

Lunex Stealer, also known as Psychedelic Stealer, is a malware-as-a-service platform distributing information-stealing malware through compromised Ukrainian websites using fake CAPTCHA pages via ClickFix. The attack chain uses a malicious AMD driver (PDFWKRNL.sys) exploiting CVE-2023-20598 to bypass security monitoring via the BYOVD technique, enabling privilege escalation and evasion of EDR solutions. The malware steals credentials from multiple Chromium-based browsers, exfiltrates cryptocurrency wallet data, and establishes persistent remote access through a PowerShell-based Chrome Native Messaging Host. Command-and-control infrastructure includes multiple panels across 13 countries, with phishing domains linked to at least one Turkish-hosted panel.

AI-extracted · verify before operational use

Indicators of Compromise 6 extracted

Type Value Detail
IP 193[.]178[.]159[.]128 Details →
Domain account-sams-club[.]com Details →
Domain teamwork-recover-password[.]com Details →
Domain namshi-uae[.]com Details →
Domain whatsappbusineses[.]com Details →
Domain ibraq-perfumes[.]com Details →