Lunex stealer malware

Understanding the Lunex Stealer Malware: Attack Chain, Tactics and Defense

Lunex is a malware-as-a-service platform distributing a credential-stealing malware known as Psychedelic Stealer, which has recently been found using compromised Ukrainian websites and fake CAPTCHA pages to infect victims. The malware's most dangerous capability is its abuse of legitimate AMD drivers to disable antivirus monitoring before extracting browser passwords and cached login data. Understanding how this attack works and why it succeeded against security software will help you recognise similar phishing attempts and protect your credentials.

Lunex Stealer: How the Malware Disables Security and Steals

What is Lunex and How It Operates

Lunex is a malware-as-a-service (MaaS) platform that distributes information-stealing malware to customers who lack the technical skills to write their own. The platform operates by packaging a credential stealer called Psychedelic Stealer and distributing it through a four-stage infection chain designed to evade detection and establish persistent access to victim systems. Rather than relying solely on social engineering, Lunex combines fake verification pages, driver-level privilege abuse and legitimate-looking error dialogs to reduce user suspicion and security software interference.

The MaaS model means multiple operators rent access to the Lunex platform and use it for their own campaigns. This decentralised distribution approach makes it harder for defenders to track a single attacker and allows the platform operators to profit from a stream of rental fees. Security vendors investigating Lunex have documented activity targeting primarily Ukrainian-speaking users, though the tactics used are portable and likely to be adapted for other regions and languages.

The Four-Stage Attack Chain: How Victims Get Infected

The infection process follows a deliberate sequence designed to build false trust and bypass both human judgement and automated defences.

  1. Victims land on a compromised or malicious Ukrainian website after clicking a malicious link, often from email or messaging platforms.
  2. A fake CAPTCHA verification page appears, mimicking legitimate Cloudflare security checks. This page requests browser interaction and creates a sense of routine security procedure.
  3. If the victim completes the fake CAPTCHA, the malware download begins, often disguised as a legitimate system update or application.
  4. Once executed, the malware establishes persistence, disables security monitoring and begins harvesting credentials from web browsers.

This staged approach is effective because each step feels plausible in isolation. A Cloudflare-like verification page is something millions of users encounter daily, making it a convincing social engineering vector. The timing and context reduce user scrutiny and allow the malware to execute before antivirus software can react.

Abusing AMD Drivers to Bypass Security Software

The most technically notable aspect of Lunex is its abuse of legitimate AMD display drivers to disable endpoint detection and response (EDR) tools. Security software typically runs at kernel level to monitor system activity, but driver-level access can sometimes exceed or bypass those protections. By loading a signed, legitimate AMD driver and then exploiting known weaknesses or misconfigurations in how it operates, the malware gains the ability to suppress or blind security monitoring.

This technique is sometimes called a "Bring Your Own Vulnerable Driver" (BYOVD) attack. The driver itself is not malicious, but the malware leverages it as a tool to achieve privilege escalation and security evasion. The effectiveness of this approach depends on the target system's driver versions, patch level and security software architecture. Older or unpatched systems are significantly more vulnerable. Once security monitoring is disabled, the malware operates with minimal risk of detection by tools that normally alert on credential access or suspicious process behaviour.

What Happens After Infection: Credential Harvesting

Once Lunex disables security monitoring, the malware focuses on extracting credentials from installed web browsers. Modern browsers store login data in encrypted databases, but they keep decryption keys accessible to the running process. Lunex extracts these keys and uses them to decrypt stored passwords for online banking, email, social media and other services.

The malware also harvests browser cache, cookies and autofill data, which together form a detailed map of the victim's online activity and accounts. This harvested data is transmitted to attacker-controlled servers, typically encrypted to prevent interception. Once stolen, credentials are often resold on underground forums or used directly by the attackers to access financial accounts or corporate networks. For business victims, a single infection can lead to lateral movement, ransomware deployment or data exfiltration.

Why This Attack Succeeded: The Human and Technical Factors

Lunex succeeded because it exploited a gap between user awareness and technical reality. Most users are trained to recognise obvious phishing, but a fake Cloudflare verification page paired with a compromised Ukrainian website creates high perceived legitimacy. The ClickFix-style social engineering (mimicking legitimate security prompts) deliberately lowered user suspicion, making people more likely to click or download.

On the technical side, the abuse of AMD drivers revealed that many antivirus tools struggle to defend against kernel-level privilege escalation, especially when the escalation is achieved through legitimate, signed drivers. Systems running older driver versions or unpatched Windows installs were particularly exposed. The combination of strong social engineering with a sophisticated technical evasion technique meant that even users with security software installed could be compromised if that software lacked advanced driver-level protection.

How to Recognise and Avoid Lunex and Similar Attacks

Defending against Lunex and related malware requires habits across multiple layers.

  • Be suspicious of unexpected verification pages, even if they look like Cloudflare or other trusted services. Legitimate verification pages typically appear within your browser normally, not as pop-ups or redirects to unfamiliar sites.
  • Check the website URL before interacting with any form or button. A legitimate Cloudflare page will be hosted on the domain you originally visited, not on a separate attacker-controlled site.
  • Keep your operating system, drivers and antivirus software fully patched. Outdated drivers are a common vector for privilege escalation attacks like the one Lunex uses.
  • Use a password manager to generate and store unique passwords for each account. If one service is compromised, this limits the damage to that single account.
  • Enable two-factor authentication (2FA) on sensitive accounts like email, banking and social media. Even if your password is stolen, 2FA prevents immediate account takeover.
  • Avoid clicking links in unsolicited emails or messages, especially if they claim to verify your identity or warn of security issues. Navigate to the site directly in your browser instead.

The Broader Threat: Why MaaS Platforms Matter

The rise of malware-as-a-service platforms like Lunex is significant because it lowers the barrier to entry for cybercriminals. Previously, an attacker needed to be skilled enough to write malware, test it, distribute it and handle the stolen data. Now, someone with minimal technical knowledge can rent access to Lunex and run their own credential-stealing campaign. This democratisation of malware distribution means attacks will likely become more frequent, more varied in targeting and harder to attribute to a single group.

Law enforcement typically attempts to disrupt MaaS platforms by seizing infrastructure, arresting operators or taking down payment channels. However, the decentralised nature of these operations means that even after a platform's takedown, the techniques and code are often reused by other groups. Understanding how these platforms work helps security teams anticipate future attacks and recognise patterns, even when the malware is rebranded or slightly modified.

Immediate Steps to Protect Yourself

If you use web browsers for work or personal finance, your threat landscape from malware like Lunex is real. The best immediate action is to conduct a password reset on your most sensitive accounts, particularly email and banking, using a clean device or browser that has not been exposed to suspicious links. This limits the window an attacker has to use stolen credentials. Change your passwords from a different device than the one potentially infected, so the malware cannot intercept the new passwords in real time.

Next, enable two-factor authentication on every account that offers it, starting with email, banking and social media. These are the accounts that, if compromised, cause the most harm. Document your actions so you can follow up if you notice suspicious activity on any account. Finally, download and run a reputable antivirus scanner in safe mode if you suspect infection, though be aware that sophisticated malware like Lunex may have already disabled some security tools by the time you detect it. If you operate a business, consider contacting your IT security team or a forensic incident response firm if you suspect exposure.

Source: The Hacker News