Image: The Hacker News
Windows users, particularly Ukrainian speakers, are being targeted through compromised websites that display fake Cloudflare verification checks. The resulting Lunex infection can weaken security monitoring, steal browser credentials and cryptocurrency wallet data, and retain remote access.
What users should watch for
The Hacker News reports that Ontinue traced the activity to a four-stage attack aimed at Ukrainian-speaking users. Attackers compromise legitimate websites and use fake CAPTCHA pages to persuade visitors to run bogus MSI installers, which are Windows installation packages.- Close any verification page that asks you to copy and run a Windows command or installer.
- If you followed such instructions, disconnect the PC from the network and run a full scan with your security software or seek incident-response help.
- From a known-clean device, change passwords stored in Chrome, Edge, Brave, Yandex Browser, Opera, Opera GX or Vivaldi, revoke active sessions, and review cryptocurrency wallets for unauthorized activity.
Security tools can remain open but lose visibility
Ontinue found that the LunexLoader component exploits the vulnerable AMD Radeon driver PDFWKRNL.sys through CVE-2023-20598. This “bring your own vulnerable driver” technique gives malware a route into the Windows kernel, where it can interfere with security-related processes.The malware reportedly alters kernel callbacks instead of terminating security software. That means a protection product may still appear to be running even though part of its monitoring has been blinded; it does not necessarily mean every defense on the PC has been disabled.
Passwords, wallets and lasting browser access
LunexStealer targets credentials in seven Chromium-based browsers and data from several desktop and browser-extension wallets. It also collects session cookies, which may let an attacker reuse an already authenticated browser session.Ontinue also identified persistence through a Registry Run key, a hidden scheduled task named “psychedelicloveUtils,” and a Chrome native-messaging host. The PowerShell-based host can survive removal of the original stealer file, reboots and browser restarts while supporting file access and program execution.