Lunex Stealer가 AMD 드라이버를 악용해 보안 모니터링을 비활성화하고 브라우저 자격 증명을 탈취하는 공격이 발생했다.
Lunex Stealer는 우크라이나 웹사이트를 통해 배포된 멀웨어로, ClickFix 스타일의 Cloudflare 검증을 이용하여 사용자를 대상으로 하며, 전체 공격에는 네 단계의 체인이 있다. 최신 보고서에 따르면, 이 악성 코드는 AMD 드라이버를 악용하여 보안 모니터링을 비활성화하고 브라우저 자격 증명을 훔친다. 이러한 방식은 Yahoo와 같은 주요 사이트에서 접속을 유도해 사용자의 정보를 탈취하는 공격의 일환이다.
Lunex Stealer abuses AMD drivers to disable security monitoring and steal browser credentials in a multi-stage attack.
Lunex Stealer is a malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare checks to target users. The attack involves a four-stage chain, exploiting AMD drivers to disable security monitoring and steal browser credentials. The recent findings highlight a broader malware-as-a-service platform's capabilities in orchestrating such sophisticated attacks.