CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8654

As cited

Copy frozen at (site build).

threat intel

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

Lunex Stealer, distributed through compromised Ukrainian websites using fake CAPTCHAs and ClickFix-style Cloudflare verification checks, abuses AMD drivers to disable security monitoring and steal browser credentials. Security researchers from Ontinue identified the malware as part of a malware-as-a-service (MaaS) platform targeting Ukrainian-speaking users through a four-stage attack chain.

Why it matters: Organizations and users in Ukraine and Russian-speaking regions face credential theft and disabled endpoint protections; defenders should monitor for Lunex distribution patterns and validate driver loading controls.

VendorsCloudflare
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary