A Dangerous New Threat: The Lunex Stealer
A newly discovered malware-as-a-service (MaaS) platform known as Lunex is raising alarms for its sophisticated approach to bypassing system defenses. Unlike standard information stealers that simply attempt to bypass antivirus software, Lunex employs a 'Bring Your Own Vulnerable Driver' (BYOVD) strategy to physically blind security tools, effectively turning them off while keeping the processes running.
How the Attack Works
The attack chain is a meticulously crafted four-stage process currently targeting Ukrainian-speaking users via compromised websites. The infection begins with 'ClickFix'-style prompts—fake Cloudflare verification checks that trick users into downloading a malicious MSI installer. Once executed, the following sequence occurs:
- Infection delivery: A fake CAPTCHA triggers the download of the malicious MSI installer.
- Privilege escalation: The LunexLoader uses the CMSTPLUA COM object to bypass User Account Control (UAC).
- Driver exploitation: The malware drops a vulnerable kernel-mode driver from AMD Radeon Software (PDFWKRNL.sys).
- Security blindside: Using the driver's vulnerability (CVE-2023-20598), the malware deactivates security monitoring, allowing the final stealer payload to harvest browser data, cryptocurrency wallets, and sensitive files undisturbed.
The Danger of BYOVD Attacks
The use of the PDFWKRNL.sys driver is particularly concerning because the driver is legitimate and Authenticode-signed, making it difficult for standard security solutions to flag it as inherently malicious. CVE-2023-20598, the specific vulnerability involved, is a design flaw in the IOCTL handler that has been known since 2023. By leveraging this existing 'LOLDriver' (Living Off the Land driver), attackers can escalate privileges to the kernel level, giving them total control over the operating system’s security posture.
What distinguishes this Lunex campaign is the integration of PDFWKRNL.sys into a multi-stage delivery chain with PDB-guided callback zeroing rather than blind execution.
— Ontinue Research
