Sep 29, 2026 · 6 min read
Lunex Stealer Uses AMD Driver to Blind EDR, Steal Cookies
A new malware as a service platform drops a signed AMD Radeon driver, zeroes the kernel callbacks security tools depend on, and then takes the passwords and session cookies out of seven Chromium browsers. The EDR keeps running the whole time.
Most infostealers try to outrun endpoint detection. Lunex leaves it running and simply stops it from seeing anything. On September 24, 2026, Ontinue researcher Rhys Downing published a technical teardown of LunexStealer, describing a four stage chain that starts on a fake Cloudflare check and ends with a PowerShell backdoor living inside the victim's browser.
The part defenders should notice first: Downing says neither HVCI nor Microsoft's current Vulnerable Driver Blocklist stops the specific driver variant Lunex uses.
Key Takeaways
- Ontinue documented LunexStealer on September 24, 2026, as the payload of a malware as a service platform called Lunex that sells to multiple criminal groups.
- PDFWKRNL.sys, an AMD Radeon Software driver vulnerable to CVE-2023-20598, is loaded to zero kernel callbacks so EDR products keep running but stop receiving events.
- Seven Chromium browsers are targeted, and session cookies and tokens go to a dedicated C2 endpoint,
/api/v1/ext/tokens, separate from passwords. - A PowerShell native messaging host registered as
com.lunex.explorersurvives deletion of the stealer binary, reboots and browser restarts. - Lunex panels grew from 6 in June 2026 to 28 across 13 countries by the time of Ontinue's report.
What Is Lunex Stealer?
Lunex Stealer is a Windows infostealer sold through a malware as a service platform named Lunex, and its victim side binary is called Psychedelic. The Hacker News write up credits Ontinue, Arctic Wolf Labs and BlueTeamCoolTeam with the research, and describes the developer as Russian speaking.
BlueTeamCoolTeam's Luke Wilkinson first spotted six live command and control panels in June 2026. By Ontinue's report, internet wide scanning had found 28 panels in 13 countries, hosted in Russia, the U.S., the U.K., the Netherlands, France, Germany, Turkey and Bangladesh. That is more than four times the footprint in roughly three months, which is what a platform with paying affiliates looks like.
The observed campaign targets Ukrainian speaking users. Attackers compromised small Ukrainian business websites, including a hair treatment clinic, a bookseller and an automotive retailer, and injected iframes serving a ClickFix style fake Cloudflare verification that pushes a bogus MSI installer.
How Does the BYOVD Stage Blind EDR?
LunexLoader drops PDFWKRNL.sys, a legitimately signed AMD Radeon Software driver with the known flaw CVE-2023-20598, and uses its kernel access to zero out the callbacks security products register. Downing calls this "PDB guided kernel callback zeroing rather than process termination," a quieter approach that "leaves security products running but blind," per The Hacker News.
Before that, the loader bypasses UAC through the CMSTPLUA COM object. It then pulls debug symbols from Microsoft's public symbol server so it can find the exact kernel structures to patch. The driver hash has sat in the LOLDrivers project since March 2026, yet the blocklist gap remains.
This matters for triage. A dashboard showing healthy, reporting agents is not evidence a host is clean if Lunex already ran there.
What Data Does Lunex Steal?
Lunex steals saved passwords, cookies, session and authentication tokens, card data and autofill entries from Chrome, Edge, Brave, Yandex, Opera, Opera GX and Vivaldi, plus nine crypto wallets. According to Ontinue's analysis, the binary skips the SQLite library and reads browser databases with its own B-tree page parser, and it handles Chrome's v10, v11 (App-Bound Encryption) and v20 encryption formats.
Exfiltration is plain HTTP POST with JSON bodies to three endpoints:
/api/v1/ext/passwordsfor credentials/api/v1/ext/tokensfor session cookies and tokens/api/v1/ext/walletsfor zipped wallet files
Every request carries a static X-API-Key header, which makes a clean network signature.
Why Is the Native Messaging Host the Real Persistence?
Because it lives in the browser's own plumbing and outlasts the stealer. Chrome's native messaging documentation shows that any installer can register a host under HKCU\SOFTWARE\Google\Chrome\NativeMessagingHosts, no admin rights required. Lunex registers com.lunex.explorer there and in the matching Edge key, backed by a 13,200 byte PowerShell script.
That script exposes six actions: list_drives, list_dir, read_file (up to 524 MB in 512 KB chunks), write, download and run. A companion extension is planted by editing Chrome's Secure Preferences and requests cookies, tabs, proxy, scripting and access to all HTTP and HTTPS URLs. Ontinue flags the host key as the step responders most often miss during cleanup.
Why Email Users Should Care
A session cookie for Outlook on the web or Gmail is a logged in mailbox, and a dedicated /tokens endpoint tells you the operators value those cookies separately from passwords. Replaying a stolen session skips the password prompt and the MFA prompt entirely. We saw the same payoff in NovaCookies' abuse of real Docusign emails and in infostealers hijacking Claude sessions.
Here is the implication chain the source reports stop short of. The Lunex extension holds the cookies permission and all URL access, and the native host survives binary deletion. So rotating a password on a Lunex host does not end the exposure. A fresh webmail session created on that same machine is readable again. Mailbox recovery has to begin with reimaging the endpoint, then revoking sessions, then resetting credentials, in that order.
Stolen mailbox logins also have a long shelf life, as the 48 million Gmail logins found in one infostealer dump showed.
How Should Defenders Hunt and Respond?
Hunt the stages that happen before EDR goes blind, then check for the persistence that survives it. Indicators below come from Ontinue's report.
- Symbol downloads: non development processes fetching PDBs from
msdl.microsoft.com/download/symbols/. - Driver drops: PDFWKRNL.sys written to temp directories, or service creation for drivers from nonstandard paths. SHA-256
6e8b49cf70bf854e8c59c7d27cefa89406caf8978461190dabb86dafcd8554e1. - Persistence:
NativeMessagingHosts\com.lunex.explorer, scheduled taskpsychedelicloveUtils, mutexLocal\psychedeliclove-guard. - Network:
193.178.159[.]128on ports 8080 and 8000,107.175.82[.]242:9000, and delivery domainuasputnik[.]com. - Cleanup: remove the binary, task, Run key, native host key and the extension entry in Secure Preferences, then invalidate every credential and session the browser held.
Where WDAC is in use, add an explicit deny rule for the PDFWKRNL.sys hash rather than waiting on the Microsoft blocklist to catch up.