# Lunex malware uses vulnerable AMD driver to blind security tools

_Published Saturday, September 26, 2026 at 4:07 PM EDT · Security · Latest · Tier 2 — Notable_

![Lunex malware uses vulnerable AMD driver to blind security tools — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjlKEfNLMvV7mEVtxmw1nS48l0bWRxvhvRH5MHdn20FjDTm6B0_5okfLjQ49AamYo9DPVC1aV1O2bl11Vd8776ziWsV96tcxQviDK0RjOnGK_Dyx_Zs2e2VBjgChf91_H2cHH0u_UoyAGlGlJkKnozWFqf-sxmXNW0QlnfY3Ilgdkg3p4qG7p3Z0SmdnJMq/s1700-nu-rw-lo-l85-e365/stealer-malware.jpg)

Security researchers at Ontinue traced a credential-stealing campaign aimed at Ukrainian-speaking users to Lunex, a malware platform sold to criminal groups. Its loader uses a vulnerable AMD Radeon driver to gain elevated access and blind security tools while their processes keep running. The stealer then takes browser passwords, session cookies and cryptocurrency wallet data, and installs a component that preserves remote access through the browser.

Ontinue identified 28 Lunex control panels across 13 countries, compared with six identified in June. In tests, neither Windows memory integrity protection nor Microsoft's current vulnerable-driver blocklist stopped the driver variant used in this attack chain from loading.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/lunex-stealer-abuses-amd-driver-to.html)

---
Canonical: https://techandbusiness.org/newswire/ZuHTcpqG3ZkeTE4LrUC2cu
Published: 2026-09-26T20:07:02.957Z
Story chronology: 2026-09-26T18:22:52.000Z
Retrieved: 2026-09-26T21:53:51.656Z
Publisher: Tech & Business (techandbusiness.org)
