Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
Ontinue details LunexStealer MaaS using BYOVD with AMD's PDFWKRNL.sys (CVE-2023-20598) to blind EDR before stealing credentials and crypto wallets.
Ontinue describes a four-stage chain starting with ClickFix fake-CAPTCHA pages injected into compromised Ukrainian websites, delivering MSI loaders that launch LunexLoader, which bypasses UAC via the CMSTPLUA COM object and abuses AMD's vulnerable PDFWKRNL.sys driver (CVE-2023-20598) to blind security processes while leaving them running. LunexStealer harvests credentials from seven Chromium-based browsers, enumerates desktop and browser-extension cryptocurrency wallets, and persists via a Registry Run key, a hidden scheduled task, and a PowerShell-based Chrome Native Messaging Host. 28 active C2 panels across 13 countries indicate rapid expansion of the Russian-speaking-developed MaaS platform. Testing showed neither HVCI nor Microsoft's Vulnerable Driver Blocklist stops this driver variant.