Lunex Stealer abuse of AMD driver escalates threat
🛡️ Ontinue details a four-stage attack chain distributing Psychedelic (LunexStealer) via compromised Ukrainian sites using ClickFix-like CAPTCHA lures. The chain uses bogus MSI installers to deploy LunexLoader, bypass UAC, and leverage a vulnerable AMD Radeon driver (PDFWKRNL.sys, CVE-2023-20598) for BYOVD-based defense evasion before installing a PowerShell-backed native messaging host. The stealer harvests browser credentials, cookies, and desktop and extension cryptocurrency wallets while persisting via registry, scheduled tasks, and a malicious Chrome extension.