Skip to content
Lunex Malware Targets Ukrainian Users with BYOVD Exploit

Lunex Malware Targets Ukrainian Users with BYOVD Exploit

First seen 27 Sep 2026, 09:21 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 27, 2026 at 18:20 UTC
  • •Lunex malware targets Ukrainian users via a four-stage attack chain.
  • •BYOVD technique used to disable security monitoring before deploying the stealer.
  • •CVE-2023-20598 exploited in AMD drivers to escalate privileges.

The Lunex Malware-as-a-Service platform has been identified as targeting Ukrainian-speaking users through a sophisticated four-stage attack chain. The attack begins with a fake CAPTCHA page and employs a Bring Your Own Vulnerable Driver (BYOVD) technique to disable security monitoring before deploying the LunexStealer, which extracts credentials from seven Chromium-based browsers and exfiltrates cryptocurrency wallets. The malware exploits a vulnerability in the AMD Radeon driver (CVE-2023-20598) to escalate privileges and evade detection. The Lunex platform has been linked to Russian-speaking threat actors, with 28 command-and-control panels identified across 13 countries. This malware campaign is notable for its method of using legitimate drivers to bypass security measures, making it a significant threat to affected users. The attack chain was first documented in detail by Ontinue Cyber Defence Centre on September 27, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2023-10-17
CVE-2023-20598 published
AMD disclosed a vulnerability in its Radeon driver that could allow arbitrary code execution, exploited by Lunex malware.
AMD
2026-09-25
Lunex malware linked to Russian actors
Security Magazine reported that Lunex is associated with a financially motivated, CIS-aligned threat actor targeting Ukrainians.
Security Magazine
2026-09-27
Lunex malware analysis published
Ontinue Cyber Defence Centre released a detailed analysis of the Lunex Malware-as-a-Service platform, revealing its four-stage attack chain targeting Ukrainian users.
Ontinue
2026-09-27
Lunex Stealer identified
The Lunex Stealer was identified as part of a malware campaign exploiting compromised Ukrainian websites.
The Hacker News

More articles in this cluster (6)

Following this threat?

Track CVE-2023-20598 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed