Threats & Adversaries · Credential Theft

Lunex Uses AMD Driver to Blind EDR

Ontinue found Lunex, also tracked as Psychedelic Stealer, using AMD's PDFWKRNL.sys driver and CVE-2023-20598 to turn off kernel security callbacks before stealing Chromium-browser credentials, session cookies, and cryptocurrency wallets. The malware is delivered through a four-stage chain that starts with a fake CAPTCHA page and a booby-trapped installer.

The driver abuse matters because the security tools stay running while their kernel hooks go blind, so endpoint monitoring can miss the credential-theft phase entirely. Ontinue also says the malware installs a PowerShell-based native messaging host inside the browser, giving the operator persistent remote access through the browser layer even after the first theft run.

That leaves a durable exposure wherever a team depends on EDR to see browser theft in time. The important question is not just whether the stealer runs, but whether an attacker can reuse a signed vulnerable driver to keep security software present and ineffective.

1 source · 3h ago

CVE-2023-20598

NVD KEV

CVSS 7.8 HIGH: An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft… EPSS 0.5% (37th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-09-26

Every edition of this story: Lunex Uses AMD Driver to Blind EDR

More from today