Threat Intelligence

New Lunex Stealer Uses Fake CAPTCHA Pages and a Vulnerable AMD Driver to Blind Security Tools

The Hacker News · 27 Sept 2026
Key Takeaway Train staff to be suspicious of unexpected CAPTCHA or verification prompts on websites, and keep device drivers and security software updated to reduce exposure to known vulnerabilities.

Researchers at Ontinue have uncovered a new malware-as-a-service platform called Lunex, which powers the Psychedelic Stealer malware recently spread through compromised Ukrainian-language websites. The attack begins with a fake CAPTCHA verification page (a technique known as ClickFix) that tricks victims into running a malicious MSI installer. This installer deploys a loader that bypasses Windows security prompts and ultimately installs the stealer payload.

What makes this campaign notable is its use of a legitimate but vulnerable AMD Radeon graphics driver (affected by CVE-2023-20598) to gain deep system access and disable security monitoring tools, a technique known as 'bring your own vulnerable driver'. With defences switched off, the stealer harvests saved credentials and session cookies from seven Chromium-based browsers, along with cryptocurrency wallet data, and sets up ongoing remote access to the victim's machine.

The malware has so far been distributed through injected code on compromised legitimate websites, including a hair-treatment clinic, a bookseller, and an automotive retailer, showing that attackers are increasingly hijacking trusted small business sites to reach victims.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.