Lunex malware service uses AMD driver to evade defenses and harvest browser data

A malware-as-a-service platform called Lunex is linked to Psychedelic Stealer, which has been spread through compromised Ukrainian sites using fake Cloudflare verification pages. Researchers at Ontinue say the operation uses a four-stage attack chain aimed at Ukrainian-speaking users. The malware reportedly abuses an AMD driver to interfere with security monitoring and steal browser credentials.
Lunex is described as a service that provides malware to other actors and is tied to Psychedelic Stealer. Ontinue researchers say it reached people through breached Ukrainian websites showing counterfeit Cloudflare verification prompts. The campaign reportedly used a four-step intrusion sequence and focused on Ukrainian-language targets.
The operation is said to leverage an AMD driver to hamper defensive oversight and gather browser-stored login data. No further technical specifics are available from the provided material.
Ukrainian-speaking internet users may face greater risk of credential theft and account takeover. Organizations whose staff visit compromised sites could have browser-saved passwords exposed, potentially enabling fraud or further intrusions. Because such malware is offered to other criminals, lower-skilled actors might adopt similar evasion methods, possibly increasing pressure on defenders. The reported use of an AMD driver may prompt security teams to review monitoring gaps, though real-world impact depends on adoption and mitigation.