Lunex Stealer Exploits AMD Driver to Bypass Security and Harvest Browser Logins
A new variant of the Lunex Stealer malware has been found leveraging a legitimate AMD graphics driver to disable security monitoring tools and exfiltrate saved browser credentials, according to research released by cybersecurity firm Ontimize.
The malicious code is part of a broader malware‑as‑a‑service (MaaS) ecosystem known as Lunex, which offers affiliates a modular toolkit for stealing data, installing additional payloads, and evading detection. The platform has been active for several years, but this latest iteration marks a notable escalation in its technical sophistication.
Ontimize’s analysis shows the stealer loading an unsigned AMD driver component that runs with kernel‑level privileges. By manipulating the driver, the malware can temporarily suspend endpoint protection services and other security sensors, creating a window in which credential harvesters operate unchecked. The technique mirrors tactics previously seen in more advanced threats that co‑opt legitimate drivers to hide their activity.
Distribution of the payload continues to rely on compromised websites hosted in Ukraine. Attackers have inserted malicious scripts that trigger a ClickFix‑style Cloudflare verification page, a social‑engineering trick that mimics the browser’s security challenge. Users who complete the fake verification are silently redirected to a downloader that installs the stealer without further prompting.
Once installed, the malware scans popular browsers for stored passwords, cookies, and session tokens, then forwards the data to command‑and‑control servers operated by the Lunex service. The stolen credentials can be used for financial fraud, account takeover, or sold on underground markets, amplifying the threat’s impact beyond the initial infection.
Security experts note that abusing a legitimate graphics driver complicates detection, as traditional antivirus signatures may not flag the driver itself. The incident underscores a growing trend where threat actors weaponize trusted system components to bypass defenses, a challenge that forces defenders to adopt behavior‑based monitoring and stricter driver signing policies.
Ontimize recommends that organizations and individual users keep graphics drivers up to date, enforce strict application whitelisting, and monitor for abnormal driver loading patterns. Vendors are expected to issue updated driver signatures and mitigation guidance, while law‑enforcement agencies continue to track the infrastructure supporting the Lunex MaaS operation.
Comments (0)
Be the first to comment.
Join the discussion