Lunex Stealer Targets Ukrainian Users via Fake CAPTCHA Pages
A new malware campaign uses compromised websites and AMD driver exploits to steal browser credentials. Security monitoring is disabled as part of a multi-stage attack.
TL;DR
- Lunex Stealer targets Ukrainian-speaking users through fake CAPTCHA pages.
- Attack chain includes disabling security tools using an AMD driver vulnerability.
- Malware steals browser credentials and operates as a MaaS platform.
- Compromised sites use Cloudflare-style verification to appear legitimate.
- Ontinue researchers uncovered the four-stage infection process.
Cybercriminals are leveraging a malware-as-a-service platform known as Lunex Stealer to target Ukrainian-speaking internet users. The initial access vector involves compromised websites presenting fake CAPTCHA challenges that mimic legitimate Cloudflare verification processes.
Once victims interact with these deceptive prompts, they are exposed to a sophisticated four-stage attack sequence designed to evade detection, disable endpoint security solutions, and ultimately exfiltrate sensitive browser-based credentials.
Attack Chain Breakdown
- Initial compromise occurs through fake CAPTCHA pages on hacked Ukrainian websites.
- Attack mimics legitimate Cloudflare verification flows to gain user trust.
- Second stage deploys Psychedelic Stealer payload with elevated privileges.
- Third stage abuses a vulnerable AMD driver to terminate security monitoring processes.
- Final stage collects and transmits stolen browser credentials to attacker-controlled infrastructure.
Technical Evasion Tactics
- Uses legitimate-looking domain verification flows to bypass user suspicion.
- Exploits AMD driver vulnerabilities to disable endpoint detection tools.
- Employs multi-stage execution to avoid static analysis and sandbox detection.
- Targets specific language settings to focus on Ukrainian-speaking demographics.
- Operates as a modular malware-as-a-service platform with credential harvesting capabilities.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.