MalwareTips News Lunex malware uses fake CAPTCHA checks to steal browser passwords and wallets

Have you ever seen a website verification page ask you to run a Windows command or installer?

  • Yes, and I closed it

    Votes: 2 20.0%
  • Yes, and I followed it

    Votes: 0 0.0%
  • No, never

    Votes: 7 70.0%
  • I am not sure

    Votes: 1 10.0%

  • Total voters
    10

News Now

Happening Now
Thread author
Verified
Sep 8, 2026
31
73
1
MalwareTips-news-121.jpg

Image: The Hacker News

Windows users, particularly Ukrainian speakers, are being targeted through compromised websites that display fake Cloudflare verification checks. The resulting Lunex infection can weaken security monitoring, steal browser credentials and cryptocurrency wallet data, and retain remote access.


What users should watch for​

The Hacker News reports that Ontinue traced the activity to a four-stage attack aimed at Ukrainian-speaking users. Attackers compromise legitimate websites and use fake CAPTCHA pages to persuade visitors to run bogus MSI installers, which are Windows installation packages.

  • Close any verification page that asks you to copy and run a Windows command or installer.
  • If you followed such instructions, disconnect the PC from the network and run a full scan with your security software or seek incident-response help.
  • From a known-clean device, change passwords stored in Chrome, Edge, Brave, Yandex Browser, Opera, Opera GX or Vivaldi, revoke active sessions, and review cryptocurrency wallets for unauthorized activity.

Security tools can remain open but lose visibility​

Ontinue found that the LunexLoader component exploits the vulnerable AMD Radeon driver PDFWKRNL.sys through CVE-2023-20598. This “bring your own vulnerable driver” technique gives malware a route into the Windows kernel, where it can interfere with security-related processes.

The malware reportedly alters kernel callbacks instead of terminating security software. That means a protection product may still appear to be running even though part of its monitoring has been blinded; it does not necessarily mean every defense on the PC has been disabled.

Passwords, wallets and lasting browser access​

LunexStealer targets credentials in seven Chromium-based browsers and data from several desktop and browser-extension wallets. It also collects session cookies, which may let an attacker reuse an already authenticated browser session.

Ontinue also identified persistence through a Registry Run key, a hidden scheduled task named “psychedelicloveUtils,” and a Chrome native-messaging host. The PowerShell-based host can survive removal of the original stealer file, reboots and browser restarts while supporting file access and program execution.

 
having a strong foundation extension/pihole of AdBlocking and both CNAME and tracking protection gives you a full run boost in this situation
recently, i've seen a lot of influence being asserted on IPv6 and they try to, because it isn't used at all during "normal" power-user, usage.