CVE-2023-20598
CVSS 7.8 HIGH: An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft… EPSS 0.5% (37th percentile).
Threats & Adversaries · Credential Theft
Ontinue found Lunex, also tracked as Psychedelic Stealer, using AMD's PDFWKRNL.sys driver and CVE-2023-20598 to turn off kernel security callbacks before stealing Chromium-browser credentials, session cookies, and cryptocurrency wallets. The malware is delivered through a four-stage chain that starts with a fake CAPTCHA page and a booby-trapped installer.
The driver abuse matters because the security tools stay running while their kernel hooks go blind, so endpoint monitoring can miss the credential-theft phase entirely. Ontinue also says the malware installs a PowerShell-based native messaging host inside the browser, giving the operator persistent remote access through the browser layer even after the first theft run.
That leaves a durable exposure wherever a team depends on EDR to see browser theft in time. The important question is not just whether the stealer runs, but whether an attacker can reuse a signed vulnerable driver to keep security software present and ineffective.
1 source · 3h ago
CVSS 7.8 HIGH: An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft… EPSS 0.5% (37th percentile).
The Hacker News
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
Lunex uses BYOVD to disable kernel security callbacks before stealing browser credentials and cryptocurrency wallets.
originalPart of the PlainSec briefing for 2026-09-26
Every edition of this story: Lunex Uses AMD Driver to Blind EDR