← Back to Daily Briefing (AMD)

Lunex MaaS Platform Weaponizes AMD Driver CVE-2025-54517

Published September 28, 2026

The Lunex Malware-as-a-Service (MaaS) platform is deploying the Psychedelic Stealer by exploiting CVE-2025-54517 in the legitimate AMD driver amdhdl64.sys. This campaign utilizes a Bring Your Own Vulnerable Driver (BYOVD) technique to achieve unsigned kernel-mode code execution, allowing attackers to disable EDR sensors within approximately two minutes of infection. Following defense neutralization, the stealer harvests browser credentials, session cookies, and autofill data from Chrome, Edge, and Firefox. Targeting Ukrainian-speaking users via fake CAPTCHA/ClickFix social engineering prompts, the campaign has impacted approximately 12,000 endpoints, resulting in significant credential theft and an estimated $3.2M in financial losses.

  • Attack Vector and Infection Chain
  • Initial access is facilitated via compromised Ukrainian-language websites using fake CAPTCHA or "ClickFix" prompts to trick users into executing a malicious payload.
  • The payload drops the Psychedelic Stealer executable immediately following user interaction.
  • Persistence is maintained via the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\OneDriveUpdater.

  • Vulnerability and Exploitation Mechanics

  • Leverages CVE-2025-54517 in the legitimate AMD driver amdhdl64.sys to perform Bring Your Own Vulnerable Driver (BYOVD) attacks.
  • Achieves unsigned kernel-mode code execution to bypass usermode security constraints and hide malicious processes.
  • Successfully blinds or disables EDR/EDR sensors in 78% of observed infections within a two-minute window post-exploitation.

  • Impact and Data Exfiltration

  • Targets browser-stored data, including passwords, session cookies, and autofill information from Chrome, Edge, and Firefox.
  • Exfiltrates harvested data to C2 domains following the pattern hxxps://[az09]{8}.(xyz|top|online)/gate.php.
  • Over a six-week window (Sept–Oct 2026), ~12,000 endpoints were infected, yielding an average of 47 credential sets per host.
  • Total estimated financial impact exceeds $3.2M USD based on credential resale and fraud enablement.

  • Indicators of Compromise (IoCs)

  • Malware Hash (SHA-256): 3a7f1c9e4b6d8e2f5a1c9d4e6b7a8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6.
  • C2 Domain Pattern: hxxps://[az09]{8}.(xyz|top|online)/gate.php.
  • Registry Persistence: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\OneDriveUpdater.
  • Vulnerable Driver: amdhdl64.sys.

  • Mitigation and Defensive Recommendations

  • Enforce strict driver signing enforcement to prevent the loading of vulnerable or unsigned kernel-mode drivers.
  • Monitor for anomalous loads of amdhdl64.sys and unauthorized modifications to common registry persistence keys.
  • Block the identified C2 domain patterns at the DNS and proxy layers.
  • Apply official AMD driver updates or implement vendor-recommended hardening mitigations.

Related posts

  1. techjacksolutions.com — Lunex MaaS Platform Weaponizes AMD Driver to Blind Security Tools, Harvests Browser Credentials from Ukrainian Targets
  2. The Hacker News — Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
  3. Ontinue
  4. Cyberstack
  5. Verisq
  6. Inionline

LINK COPIED TO CLIPBOARD