Lunex Stealer Exploits Vulnerable AMD Driver to Blind Security Tools and Harvest Credentials
The Lunex Stealer exploits CVE-2023-20598, a known vulnerability in an AMD driver, to escalate privileges and disable endpoint security monitoring — a technique known as Bring Your Own Vulnerable Driver (BYOVD). This allows attackers to operate undetected while harvesting browser credentials and cryptocurrency wallet data across multiple stages. The attack begins with a social engineering lure (fake CAPTCHA) and progresses to full C2 agent deployment, demonstrating how unpatched drivers in the kernel layer create catastrophic blind spots for defenders. The fact that this vulnerability was disclosed in 2023 and is still being weaponized highlights the critical gap between patch availability and operational patch deployment.
Tactical Insight
Immediate actions
- Apply the vendor patch for CVE-2023-20598 immediately or blocklist the vulnerable AMD driver using Windows Defender Application Control (WDAC) or similar controls.
- Enable Microsoft's Vulnerable Driver Blocklist (HVCI) to prevent known malicious drivers from loading at the kernel level.
Long-term improvements
- Maintain a complete inventory of all installed drivers and firmware across endpoints and enforce a driver patch cadence aligned with your vulnerability management SLA.
- Implement a Bring Your Own Vulnerable Driver (BYOVD) detection strategy by integrating kernel-level telemetry into your SIEM for anomalous driver load events.
- Adopt application allowlisting policies that restrict unauthorized driver installation to reduce the kernel attack surface.
Detection measures
- Configure EDR/XDR solutions to alert on privilege escalation attempts and unexpected termination or tampering of security agent processes.
- Monitor for suspicious CAPTCHA-themed phishing delivery vectors and establish DNS/web filtering rules to block known C2 infrastructure associated with Lunex/Psychedelic Stealer.
- Implement browser credential theft detection by auditing access to browser credential stores (e.g., Login Data SQLite files) from non-browser processes.