RDS GoSOC AI — Field Notes AI-powered SOC + 16-framework compliance · 14-day free trial

Lunex Stealer Abuses AMD Driver to Blind Your Security Stack — What DoD STIG Teams Must Do Now

A four-stage MaaS attack chain is actively disabling endpoint monitoring. Here's how STIG-aligned organizations should respond in the next 30 days.

Published 2026-09-26

# Lunex Stealer Abuses AMD Driver to Blind Your Security Stack — What DoD STIG Teams Must Do Now

Ontinue researchers have documented a sophisticated four-stage attack chain tied to a malware-as-a-service platform called Lunex, which distributes a credential-stealing payload (dubbed Psychedelic Stealer) through compromised Ukrainian websites using ClickFix-style fake Cloudflare CAPTCHA prompts — and its driver-abuse technique has direct implications for any organization pursuing DoD STIG compliance.

What the Lunex Attack Chain Actually Does

The campaign begins with a convincing fake CAPTCHA page that tricks users into executing a malicious script. From there, the four-stage chain delivers Psychedelic Stealer, which exploits a legitimate AMD driver to suppress kernel-level security monitoring — a technique known as Bring Your Own Vulnerable Driver (BYOVD). With endpoint telemetry silenced, the malware harvests saved browser credentials, cookies, and session tokens before exfiltrating them to attacker-controlled infrastructure.

The Lunex platform operates as a MaaS offering, meaning the barrier to entry for less sophisticated threat actors is extremely low. Compromised Ukrainian websites serve as the initial delivery vector, but the ClickFix social-engineering lure is geographically portable and has appeared in campaigns targeting other regions.

Why DoD STIG and ACAS/SCAP Teams Should Pay Attention

DoD STIG controls exist precisely to prevent this class of attack. Several relevant control families are directly challenged by the Lunex technique:

What You Should Do in the Next 7–30 Days

Within 7 days:

Within 30 days:

Start Your STIG Readiness Assessment in 14 Days — No Credit Card Needed

RDS GoSOC AI gives your team a full multi-framework SOC and compliance platform — including DoD STIG readiness, ACAS/SCAP audit alignment, and 14 additional frameworks — from day one of your trial. Every paid feature is unlocked for 14 days at https://platform.reremrdsgosoc.com/register, with no credit card required. Once inside, open the User Guide tab to orient your team quickly, and use the Sage AI handle to ask setup questions, map controls to specific STIG findings, or model how the Lunex attack chain maps to your current control gaps. Your adversaries aren't waiting — your compliance posture shouldn't either.

---

#MSP #ManagedServices #CMMC #FedRamp #CyberSecurity #SOC #SecurityOperations #MSSP #ThreatDetection #Compliance #CloudSecurity #IdentitySecurity #SecurityMonitoring #ITServices #CyberResilience #ManagedSecurity #BusinessGrowth

Start the 14-day free trial →