Lunex Stealer Exploits AMD Driver to Bypass Security and Harvest Browser Credentials
The Lunex malware-as-a-service platform uses a malicious AMD driver to disable security monitoring and steal browser credentials, targeting Ukrainian‑speaking users via compromised sites.
Written and published by the Wepro Technology team
The Hacker News has reported that the Lunex Stealer, part of a broader malware‑as‑a‑service platform known as Lunex, is using a malicious AMD graphics driver to disable security monitoring and exfiltrate browser credentials.
Researchers at Ontinue traced the campaign to a four‑stage attack chain that begins with a fake CAPTCHA page on compromised Ukrainian websites, followed by Cloudflare‑style verification checks that mimic legitimate traffic before delivering the payload.
Once the driver is installed, it interferes with Windows security components, effectively turning off real‑time protection, while a secondary module harvests saved passwords from browsers such as Chrome, Edge and Firefox and sends them to the attackers’ command‑and‑control server.
Although the current victims are primarily Ukrainian‑speaking users, the technique demonstrates a growing trend of abusing legitimate hardware drivers to bypass endpoint defenses, a risk that Australian organisations and students must consider when hardening Windows environments.
Australian IT professionals and students can mitigate such threats by staying current with security best practices and certifications; for example, Wepro Technology offers Security+ and other cyber‑security courses that cover driver integrity checks and advanced threat detection.
Stay ahead in IT
Join 200+ Australian IT professionals getting weekly insights delivered to their inbox.
- Weekly IT news & insights
- New course announcements
- Free quiz updates
Your email
No spam, ever · Unsubscribe anytime