News / Cybersecurity
Lunex Stealer exploits an AMD flaw to disable security tools and steal sensitive data Published on 28 September 2026 by Christ-loisele (3 min read)
The malware-as-a-service Lunex Stealer, distributed via compromised Ukrainian sites, uses a critical vulnerability in the AMD Radeon Software driver (CVE-2023-20598) to neutralize security solutions before stealing credentials and crypto wallets. The campaign specifically targets French-speaking and Russian-speaking users, with a rapid expansion of its command-and-control panels internationally.
Video: Lunex Stealer - AMD Driver BYOVD Blinds EDR (Threadlinqs, YouTube)
A rapidly expanding malware-as-a-service
Lunex Stealer, a malware-as-a-service (MaaS) platform, has seen significant growth between June and September 2026, expanding from 6 to 28 command-and-control (C2) panels across 13 countries, including the United States, Turkey, the United Kingdom, and Finland, according to Pulse Adyog . This model, where criminal groups rent infrastructure for their campaigns, demonstrates a professionalization of attacks targeting Ukrainian-speaking users.
The platform combines two components: LunexLoader , which bypasses Windows User Account Control (UAC) via the COM object CMSTPLUA , and Psychedelic Stealer , a module specialized in data theft. The latter extracts credentials from seven Chromium-based browsers (including Chrome, Edge, and Brave) and exfiltrates information related to cryptocurrency wallets, according to The Hacker News .
The Lunex platform is designed to blind security tools before stealing data, exploiting a flaw in an AMD driver that Microsoft protections fail to block
Logo: AMD Radeon Software (Advanced Micro Devices, Inc., Public domain)
A three-phase attack exploiting an unpatched AMD flaw
The infection begins with a fake Cloudflare verification page, mimicking the ClickFix system, which redirects victims to a fake CAPTCHA. Once prompted to run an MSI command, they install LunexLoader, which deploys the vulnerable driver PDFWKRNL.sys (linked to AMD Radeon Software) to exploit the flaw CVE-2023-20598 , as detailed by SparTech Software .
This driver, cataloged in the LOLDrivers project since March 2026, allows privilege escalation and disables security tools (such as EDR solutions) using a technique called PDB-guided kernel callback zeroing , according to Pulse Adyog . Despite Microsoft protections (Hypervisor-Protected Code Integrity and vulnerable driver list), this specific variant bypasses these mechanisms, as noted by researcher Rhys Downing .
The final phase installs a full C2 agent, offering persistent access via a Native Messaging Host PowerShell integrated into the Chrome browser, capable of executing system actions, such as reading or writing files.
Targets and methods: Ukrainian websites compromised as bait
The campaigns target Ukrainian-speaking users through compromised legitimate websites, including businesses such as a haircare clinic, a model manufacturer, or an automobile dealer, according to RedSecureTech . The attacks use phishing domains linked to Lunex panels, such as account-sams-club[.]co , and communicate with a C2 server identified at the IP 193.178.159[.]128 .
The persistence of the malware relies on three mechanisms: a Run registry key, a hidden scheduled task (psychedelicloveUtils ), and the injection of a malicious Chrome extension via manipulation of the browser’s Secure Preferences . These techniques enable automatic reinfection and continuous data theft.
What this changes here
For businesses and government agencies in Benin and West Africa, this campaign highlights the importance of updating AMD graphics drivers , particularly on critical workstations, as the CVE-2023-20598 vulnerability remains exploitable despite general patches. Organizations using Chromium-based browsers (Chrome, Edge, Brave) should also limit extension permissions and monitor suspicious behavior through EDR solutions capable of detecting driver modifications or connections to unknown IPs such as 193.178.159[.]128.
Even legitimate websites could be compromised to spread this type of malware. A strengthened verification of Cloudflare certificates and awareness of fake CAPTCHAs or verification pages (such as ClickFix ) would be necessary. Finally, the rise of MaaS platforms like Lunex shows that cybercriminals are now targeting specific linguistic or geographic niches: Francophone businesses or those using local services could be exposed if they become secondary targets.
Sources