Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
Summary
The Lunex Stealer malware, distributed through compromised Ukrainian websites, employs a four-stage attack chain targeting Ukrainian-speaking users. This malware abuses an AMD driver to disable security monitoring, enabling it to steal browser credentials.
IFF Assessment
This malware is designed to disable security measures and steal sensitive information, posing a direct threat to defenders.
Defender Context
This incident highlights the increasing sophistication of malware that targets specific user groups and leverages legitimate system components, like AMD drivers, to evade detection. Defenders should be aware of such techniques and ensure robust endpoint detection and response (EDR) solutions are in place, along with continuous monitoring for unusual driver behavior or system process manipulation.