Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
Overview
A new malware called Lunex, which is part of a broader malware-as-a-service model, is targeting Ukrainian-speaking users through compromised websites. The attack involves a four-stage process starting with a fake CAPTCHA page designed to lure victims. Once engaged, the malware exploits an AMD driver to disable security monitoring, making it easier to steal sensitive information, such as browser credentials. This is particularly concerning as it highlights the tactics used by cybercriminals to bypass security measures and compromise user data. The findings from the cybersecurity firm Ontinue emphasize the need for increased vigilance among users, especially in regions facing heightened cyber threats.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Ukrainian-speaking users, AMD drivers, web browsers
- Action Required: Users should ensure their security software is up to date and be cautious when engaging with unfamiliar websites, especially those requiring CAPTCHA verification.
- Timeline: Newly disclosed
Original Article Summary
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAPTCHA page and
Impact
Ukrainian-speaking users, AMD drivers, web browsers
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users should ensure their security software is up to date and be cautious when engaging with unfamiliar websites, especially those requiring CAPTCHA verification.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Malware, AMD.