New Lunex Stealer Uses Fake CAPTCHA Pages and a Vulnerable AMD Driver to Blind Security Tools
Researchers at Ontinue have uncovered a new malware-as-a-service platform called Lunex, which powers the Psychedelic Stealer malware recently spread through compromised Ukrainian-language websites. The attack begins with a fake CAPTCHA verification page (a technique known as ClickFix) that tricks victims into running a malicious MSI installer. This installer deploys a loader that bypasses Windows security prompts and ultimately installs the stealer payload.
What makes this campaign notable is its use of a legitimate but vulnerable AMD Radeon graphics driver (affected by CVE-2023-20598) to gain deep system access and disable security monitoring tools, a technique known as 'bring your own vulnerable driver'. With defences switched off, the stealer harvests saved credentials and session cookies from seven Chromium-based browsers, along with cryptocurrency wallet data, and sets up ongoing remote access to the victim's machine.
The malware has so far been distributed through injected code on compromised legitimate websites, including a hair-treatment clinic, a bookseller, and an automotive retailer, showing that attackers are increasingly hijacking trusted small business sites to reach victims.