Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

Lunex stealer abuses a signed AMD driver to blind security tools, Ontinue says

The malware service leaves endpoint tools running but unable to see, then takes browser credentials, session cookies and crypto wallet data, researchers say.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Ontinue says the Lunex stealer loads a vulnerable AMD driver to switch off security monitoring while tools appear to keep running.
  • 2Ontinue says Microsoft's Vulnerable Driver Blocklist and HVCI do not stop the specific driver variant used from loading.
  • 3Ontinue found 28 Lunex control panels across 13 countries, up from six that BlueTeamCoolTeam documented in June 2026.

The news

Security firm Ontinue said on September 24 that the Lunex stealer, an information-stealing malware service, loads a vulnerable but signed AMD driver to blind endpoint security tools before it takes browser credentials, session cookies and cryptocurrency wallet data from Windows computers.

The technique is known as bring your own vulnerable driver, or BYOVD: attackers install a legitimately signed driver with a known flaw, then use it to gain kernel-level control. In this case the driver is PDFWKRNL.sys, affected by CVE-2023-20598, a flaw in software from Advanced Micro Devices (AMD). Ontinue researcher Rhys Downing wrote that the loader does not kill security processes. Instead it zeroes out the kernel callback entries that security products rely on, so they keep running but stop seeing activity.

Ontinue said neither the Vulnerable Driver Blocklist from Microsoft (MSFT) nor HVCI, a Windows feature that checks the integrity of kernel code, prevents the specific variant of the driver used in this chain from loading. The Hacker News reported that the gap persists even though the driver's hash has been catalogued in the LOLDrivers project, a public list of abusable drivers, since March 2026.

The infection starts with a ClickFix lure, a fake CAPTCHA page that tells the victim to paste and run a command. Ontinue said that command installs an unsigned MSI package without a Windows permission prompt. Arctic Wolf Labs, which documented the same malware as Psychedelic Stealer days earlier, found attackers injecting the lure into compromised legitimate websites, including those of a hair-treatment clinic, a bookseller and an automotive retailer, as reported by The Hacker News.

Ontinue described Lunex as a malware-as-a-service platform developed by Russian-speaking actors and sold to multiple independent criminal operators; the campaign it analysed targeted Ukrainian-speaking users. It targets browsers including Google Chrome, Microsoft Edge and Brave, and wallets such as Exodus, Electrum and MetaMask. It also persists through a Chrome Native Messaging Host, a browser helper that Ontinue said survives deletion of the stealer, reboots and browser restarts.

Internet-wide scanning found 28 unique Lunex control panels across 13 countries, Ontinue said, up from six panels that researchers at BlueTeamCoolTeam documented in June 2026. Russia hosted the most with six, followed by the United States with four and the United Kingdom with three.

The numbers

Lunex control panels found
28 across 13 countries (Ontinue)
Panels documented in June 2026
6 (BlueTeamCoolTeam, cited by Ontinue)
Panels by host country
Russia 6, United States 4, United Kingdom 3 (Ontinue)
Vulnerability in the abused AMD driver
CVE-2023-20598
Driver hash listed in LOLDrivers since
March 2026 (The Hacker News)

Why CEOs should care

For CISOs, the uncomfortable detail is that endpoint tools stay running while blind, so a console showing healthy agents is no proof of protection. Do not assume Microsoft's default driver blocklist covers this: Ontinue says it does not stop this variant. Teams using Windows application control can add their own block rule for the PDFWKRNL.sys hash listed in LOLDrivers. Ontinue advises detecting the steps before the blinding, such as symbol file downloads by non-developer processes, drivers dropped into temporary folders and new services created for drivers from unusual paths.

Stolen session cookies can let an attacker reuse a signed-in session without the password or a multifactor prompt. If Lunex is found, revoke active sessions for affected users, reset credentials saved in browsers and review whether staff should store work passwords in browsers at all. Ontinue said remediation must include the Native Messaging Host registry key, or the infection can survive cleanup.

For boards and CFOs, the delivery method is the cheapest place to cut risk. ClickFix relies on employees pasting commands they do not understand. Ask whether staff are trained to refuse any web page that asks them to run a command, and whether ordinary users can run installer commands at all. Companies holding cryptocurrency should confirm that wallet software does not sit on general-purpose employee laptops.

The bigger picture

The case shows why BYOVD remains attractive. CVE-2023-20598 was assigned in 2023, yet Ontinue says a variant of the affected driver still loads on Windows systems with Microsoft's blocklist and HVCI in place. Blocklists depend on vendors cataloguing each abusable file, and attackers only need one signed version that slips through. Pairing that with a malware-as-a-service model lets several criminal crews reuse the same capability. BlueTeamCoolTeam found six Lunex panels in June; Ontinue counted 28 in September.

What’s next

Security teams should watch for an update to Microsoft's Vulnerable Driver Blocklist that covers this driver variant, and should not wait for it before adding their own rule. With panels spread across 13 countries, companies outside Ukraine should also check their telemetry for the Lunex network indicators that researchers have published.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

LunexAMDMicrosoftOntinueBYOVD

Earlier coverage of AMD

All AMD coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.