Lunex Stealer Abuses AMD Driver to Blind Your Security Stack — What DoD STIG Teams Must Do Now
A four-stage MaaS attack chain is actively disabling endpoint monitoring. Here's how STIG-aligned organizations should respond in the next 30 days.
Published 2026-09-26
# Lunex Stealer Abuses AMD Driver to Blind Your Security Stack — What DoD STIG Teams Must Do Now
Ontinue researchers have documented a sophisticated four-stage attack chain tied to a malware-as-a-service platform called Lunex, which distributes a credential-stealing payload (dubbed Psychedelic Stealer) through compromised Ukrainian websites using ClickFix-style fake Cloudflare CAPTCHA prompts — and its driver-abuse technique has direct implications for any organization pursuing DoD STIG compliance.
What the Lunex Attack Chain Actually Does
The campaign begins with a convincing fake CAPTCHA page that tricks users into executing a malicious script. From there, the four-stage chain delivers Psychedelic Stealer, which exploits a legitimate AMD driver to suppress kernel-level security monitoring — a technique known as Bring Your Own Vulnerable Driver (BYOVD). With endpoint telemetry silenced, the malware harvests saved browser credentials, cookies, and session tokens before exfiltrating them to attacker-controlled infrastructure.
The Lunex platform operates as a MaaS offering, meaning the barrier to entry for less sophisticated threat actors is extremely low. Compromised Ukrainian websites serve as the initial delivery vector, but the ClickFix social-engineering lure is geographically portable and has appeared in campaigns targeting other regions.
Why DoD STIG and ACAS/SCAP Teams Should Pay Attention
DoD STIG controls exist precisely to prevent this class of attack. Several relevant control families are directly challenged by the Lunex technique:
- Driver and kernel integrity (Application Security & Development STIG, OS STIGs): BYOVD attacks exploit the trusted status of signed drivers. STIG hardening guidance around driver allow-listing and kernel-mode code signing enforcement is designed to block unsigned or vulnerable driver loads — but only if it has been correctly implemented and verified.
- ACAS / SCAP audit alignment: The Assured Compliance Assessment Solution (ACAS) relies on continuous endpoint visibility. If a vulnerable AMD driver disables the security monitoring stack before a scan runs, your ACAS findings are incomplete by definition. Any SCAP benchmark check that assumes the sensor is healthy may return a false-compliant result.
- Credential protection (IA controls): Browser-stored credentials represent a critical pivot point. STIGs for browsers — Chrome STIG, Edge STIG — restrict saved password managers and local credential storage for exactly this reason. Organizations that have not enforced those controls are directly exposed.
What You Should Do in the Next 7–30 Days
Within 7 days:
- Audit your endpoint driver inventory for known-vulnerable driver signatures. Cross-reference against the Microsoft Vulnerable Driver Blocklist and confirm it is enforced via Windows Defender Application Control (WDAC) or equivalent.
- Verify that your EDR/AV sensor health is monitored out-of-band — if an agent goes dark, your SOC should alert within minutes, not days.
- Confirm browser STIGs (Chrome, Edge, Firefox) are applied and that saved-password features are disabled via Group Policy or equivalent configuration management.
Within 30 days:
- Run a full ACAS/SCAP scan sweep with explicit checks for BYOVD-relevant driver controls and compare findings to your last baseline. Investigate any delta.
- Review your MFA posture for externally accessible systems. Stolen browser session tokens can bypass password-based MFA; hardware token or certificate-based authentication reduces this risk.
- Map your STIG CAT I and CAT II open findings against the attack surface described above and prioritize remediation accordingly.
- Evaluate whether your current SOC has the continuous telemetry depth to detect driver-level tampering before credential exfiltration occurs.
Start Your STIG Readiness Assessment in 14 Days — No Credit Card Needed
RDS GoSOC AI gives your team a full multi-framework SOC and compliance platform — including DoD STIG readiness, ACAS/SCAP audit alignment, and 14 additional frameworks — from day one of your trial. Every paid feature is unlocked for 14 days at https://platform.reremrdsgosoc.com/register, with no credit card required. Once inside, open the User Guide tab to orient your team quickly, and use the Sage AI handle to ask setup questions, map controls to specific STIG findings, or model how the Lunex attack chain maps to your current control gaps. Your adversaries aren't waiting — your compliance posture shouldn't either.
---
#MSP #ManagedServices #CMMC #FedRamp #CyberSecurity #SOC #SecurityOperations #MSSP #ThreatDetection #Compliance #CloudSecurity #IdentitySecurity #SecurityMonitoring #ITServices #CyberResilience #ManagedSecurity #BusinessGrowth