Lunex Stealer Uses a Signed AMD Driver to Disable Security Tools and Harvest Credentials
A malware-as-a-service (MaaS) operation known as Lunex — previously tracked under the name Psychedelic Stealer — has been observed running a multi-stage attack chain that pairs a classic fake-CAPTCHA lure with a bring-your-own-vulnerable-driver (BYOVD) technique to disable security monitoring before stealing browser credentials, cryptocurrency wallets, and more.
What happened
Victims are lured through compromised legitimate websites carrying a fake verification page in the style of well-known "ClickFix" social-engineering lures. Completing the bogus check triggers a PowerShell-based chain that ultimately drops the Lunex stealer alongside a legitimately signed but vulnerable AMD Ryzen Master driver.
Rather than terminating security processes outright — a move that tends to trip alarms — the malware zeroes out kernel callbacks registered by AV/EDR products, a quieter technique that leaves the security agent looking alive and running while blinding its ability to see malicious activity. The driver abused is affected by a known privilege-escalation flaw, and testing showed that Microsoft's current vulnerable-driver blocklist and Hypervisor-Protected Code Integrity (HVCI) do not stop this particular exploitation path, despite the driver's hash having been public in the LOLDrivers catalogue for months.
Once monitoring is blinded, the stealer component goes to work: it lifts saved credentials from every major Chromium- and Gecko-based browser, enumerates desktop wallets (Bitcoin Core, Litecoin, Exodus, Atomic Wallet, Electrum) and browser-extension wallets (MetaMask and its legacy version, OKX Wallet, SafePal), and installs a malicious Chrome extension with sweeping permissions over cookies, history, bookmarks, tabs, and all HTTP/HTTPS traffic.
For persistence and remote access, it registers a Chrome Native Messaging Host backed by a PowerShell script running inside the browser's own process. That script supports listing drives and directories, reading and writing arbitrary files, downloading payloads, and executing programs — effectively a lightweight remote-access channel that survives deletion of the original stealer binary, reboots, and browser restarts.
Why it matters
This isn't a one-off tool. Panel analysis points to an actively maintained platform with dozens of control panels spread across more than a dozen countries — growth that suggests either a single operator scaling up or the kit being resold to multiple criminal groups. One panel was also found resolving lookalike phishing domains impersonating retail, HR, and business-messaging brands, showing the platform is used for credential phishing as well as direct theft.
The BYOVD-plus-blinding approach is the bigger concern for defenders: it specifically targets the assumption that "the EDR agent is still running, so we're covered." A process that looks healthy but has had its visibility surgically removed can leave an environment exposed far longer than an outright crash would.
What to do
- Enable attack-surface-reduction and driver-blocklist policies, and don't assume the default Microsoft vulnerable-driver blocklist covers every abused driver — validate against your specific EDR's own driver telemetry.
- Monitor for unexpected Chrome Native Messaging Host registrations, and audit installed Chrome extensions and their permissions regularly, especially ones requesting broad host access.
- Treat unexpected loading of vendor GPU/utility drivers (e.g., Ryzen Master and similar) outside normal software-update flows as a red flag worth investigating.
- Reset credentials and rotate crypto wallet keys for any user suspected of exposure, rather than assuming a clean antivirus scan after the fact is sufficient — this technique specifically defeats scan integrity.
- Be cautious with "verify you're human" pages that ask you to run a command or paste something into Run/PowerShell — that pattern is a strong ClickFix indicator regardless of which site hosts it.
