MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-26 · via The Hacker News

Lunex malware service uses AMD driver to evade defenses and harvest browser data

Image via The Hacker News
Image via The Hacker News

A malware-as-a-service platform called Lunex is linked to Psychedelic Stealer, which has been spread through compromised Ukrainian sites using fake Cloudflare verification pages. Researchers at Ontinue say the operation uses a four-stage attack chain aimed at Ukrainian-speaking users. The malware reportedly abuses an AMD driver to interfere with security monitoring and steal browser credentials.

Expanded Detail

Lunex is described as a service that provides malware to other actors and is tied to Psychedelic Stealer. Ontinue researchers say it reached people through breached Ukrainian websites showing counterfeit Cloudflare verification prompts. The campaign reportedly used a four-step intrusion sequence and focused on Ukrainian-language targets.

The operation is said to leverage an AMD driver to hamper defensive oversight and gather browser-stored login data. No further technical specifics are available from the provided material.

Context

Ukrainian-speaking internet users may face greater risk of credential theft and account takeover. Organizations whose staff visit compromised sites could have browser-saved passwords exposed, potentially enabling fraud or further intrusions. Because such malware is offered to other criminals, lower-skilled actors might adopt similar evasion methods, possibly increasing pressure on defenders. The reported use of an AMD driver may prompt security teams to review monitoring gaps, though real-world impact depends on adoption and mitigation.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at The Hacker News →
Related stories
Mac malware abuses iCloud calendar to deliver infostealer payload · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials.” Browse more stories.