Lunex stealer disables security tools before striking
Ontinue found a four-stage Lunex attack on Ukrainian speakers that uses fake CAPTCHAs and a vulnerable driver before stealing passwords and crypto.
By Sam Reyes · Published · Updated · 4 min read

Researchers at Ontinue have reverse-engineered a four-stage attack linked to the Lunex malware-as-a-service platform, the company reports.
The attack chain
- A fake CAPTCHA page tricks the victim into running an installer.
- A loader raises its privileges.
- It uses a vulnerable driver ("bring your own vulnerable driver", or BYOVD) to switch off kernel-level security monitoring.
- The final stealer, also a remote control agent, runs undetected.
The stealer was compiled on September 12, 2026, showing it is actively developed.
What it steals
- Credentials and data from seven Chromium-based browsers
- Cryptocurrency wallets
- Persistent remote access to files through a hidden browser component
Who is behind it
Ontinue believes it was built by a Russian-speaking team and sold to criminals. Researcher Rhys Downing told Security Magazine it is a "financially motivated, CIS-aligned threat actor". It targets Ukrainian-speaking users.
How to defend against it
- Never run commands or installers from CAPTCHA pages.
- Businesses should block known vulnerable drivers and alert on attempts to stop security tools.

