Lunex Stealer, a malware-as-a-service platform, has been found exploiting a vulnerable AMD driver to disable security monitoring on targeted devices. This attack chain, identified by Ontinue, specifically targets Ukrainian-speaking users through compromised websites. The attack begins with a fake CAPTCHA page and utilizes a series of steps including a vulnerable driver to evade defenses. Once security tools are disabled, the malware steals credentials and data from Chromium-based browsers, exfiltrates cryptocurrency wallets, and maintains remote access via a PowerShell-based Native Messaging Host. The Lunex Stealer employs the bring your own vulnerable driver technique to escalate privileges using a kernel-mode driver for AMD Radeon Software, which is vulnerable to CVE-2023-20598. This allows the malware to bypass security processes while they continue to run, making detection more challenging. Originating from the same platform, Psychedelic Stealer uses legitimate but compromised websites to deliver its payload. Analysis by Arctic Wolf Labs reveals that these sites range from hair-treatment clinics to automotive retailers. Once executed, Lunex Stealer communicates with its command-and-control panel, which is supported by a PowerShell script using Chrome's Native Messaging protocol. This allows it to operate even after system reboots or browser restarts. The malware also injects a malicious Chrome extension that gains extensive permissions, providing visibility and control over browser activity. The Lunex platform has rapidly expanded, with panels identified in multiple countries, indicating its active use and distribution by various threat actors. This growth highlights the platform's capability to support credential theft along with phishing and brand impersonation activities. The use of the AMD driver in the attack chain bypasses current security measures, underscoring the need for enhanced driver validation and security protocols.
Lunex Stealer Exploits AMD Driver to Evade Security and Steal Credentials
Lunex stealer abuses an AMD driver to disable security monitoring and exfiltrate browser credentials from targeted devices.
Executive Summary
PremiumActionable Insights
PremiumOriginal source
thehackernews.com

