Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

Summary

The Lunex Stealer malware, distributed through compromised Ukrainian websites, employs a four-stage attack chain targeting Ukrainian-speaking users. This malware abuses an AMD driver to disable security monitoring, enabling it to steal browser credentials.

IFF Assessment

FOE

This malware is designed to disable security measures and steal sensitive information, posing a direct threat to defenders.

Defender Context

This incident highlights the increasing sophistication of malware that targets specific user groups and leverages legitimate system components, like AMD drivers, to evade detection. Defenders should be aware of such techniques and ensure robust endpoint detection and response (EDR) solutions are in place, along with continuous monitoring for unusual driver behavior or system process manipulation.

Read Full Story →