Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
Psychedelic Stealer is being spread through compromised Ukrainian websites using ClickFix-style Cloudflare verification lures as part of the Lunex malware-as-a-service platform. The campaign uses a four-stage attack chain with a vulnerable AMD driver, stealthy security evasion, browser credential theft, wallet exfiltration, and persistent remote access via a Chrome Native Messaging Host. #PsychedelicStealer #Lunex #PDFWKRNLsys #CVE202320598

Keypoints

  • Psychedelic Stealer is delivered through fake CAPTCHA pages on compromised Ukrainian websites.
  • The malware is part of the Lunex malware-as-a-service platform.
  • LunexLoader uses UAC bypass and BYOVD techniques to disable security defenses.
  • The stealer targets browser passwords, session cookies, and cryptocurrency wallets.
  • Lunex also supports persistence, remote filesystem access, and phishing domains.

Read More: https://thehackernews.com/2026/09/lunex-stealer-abuses-amd-driver-to.html