Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Threat Intel

Lunex stealer disables security tools before striking

Ontinue found a four-stage Lunex attack on Ukrainian speakers that uses fake CAPTCHAs and a vulnerable driver before stealing passwords and crypto.

By · Published · Updated · 4 min read

Lunex stealer disables security tools before striking

Researchers at Ontinue have reverse-engineered a four-stage attack linked to the Lunex malware-as-a-service platform, the company reports.

The attack chain

  1. A fake CAPTCHA page tricks the victim into running an installer.
  2. A loader raises its privileges.
  3. It uses a vulnerable driver ("bring your own vulnerable driver", or BYOVD) to switch off kernel-level security monitoring.
  4. The final stealer, also a remote control agent, runs undetected.

The stealer was compiled on September 12, 2026, showing it is actively developed.

What it steals

  • Credentials and data from seven Chromium-based browsers
  • Cryptocurrency wallets
  • Persistent remote access to files through a hidden browser component

Who is behind it

Ontinue believes it was built by a Russian-speaking team and sold to criminals. Researcher Rhys Downing told Security Magazine it is a "financially motivated, CIS-aligned threat actor". It targets Ukrainian-speaking users.

How to defend against it

  • Never run commands or installers from CAPTCHA pages.
  • Businesses should block known vulnerable drivers and alert on attempts to stop security tools.

Sources

Read next