INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ATTENTION: This report is based on previous data. New intelligence sources have been linked and the Executive Summary and Mitigations need to be re-synthesized.

Lunex Uses BYOVD to Deploy Persistent Stealer Against Russian Companies

| 2026-10-08 02:02 LOW HIGH RANSOMWARE & EXTORTION MALWARE & BOTNETS
Executive Summary
AI-generated
On October 6, 2026, the Lunex Malware-as-a-Service platform targeted Ukrainian users through fake CAPTCHA lures, exploiting AMD's vulnerable PDFWKRNL.sys driver (CVE-2023-20598) to disable endpoint security products. The attack affected seven Chromium-based browsers and multiple cryptocurrency wallets, with a total of 7 countries being targeted in Ukraine. The attackers used the BYOVD technique to manipulate security controls, deploying LunexStealer to harvest credentials while establishing persistent C2 access through registry keys, scheduled tasks, and Native Messaging Host registrations. This mechanism survives deletion of the primary executable, providing continued filesystem access and remote execution capabilities.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2023-20598 and treat internet-facing systems that were not patched in time as potentially compromised until verified. • Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity. • Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2023-20598CVE-2023-20598
Target & Sectors
BENELUX BENELUX CENTRAL_ASIA CENTRAL_ASIA DACH DACH cryptocurrencycryptocurrency retailretail logisticslogistics manufacturingmanufacturing
Incident Timeline
‎March 2026
Microsoft's Vulnerable Driver Blocklist failed to prevent the loading of a specific PDFWKRNL.sys variant, which was previously catalogued in the LOLDrivers project since March 2026.
organisation Microsoft
organisation LOLDrivers
‎June 2026
Threat actors used Lunex Stealer's command-and-control panels to target multiple countries, including Ukraine and Russia.
target_region Ukraine
source_region Finland
source_region Germany
target_region Netherlands
general_metric 28 panels
general_metric 13 countries
source_region Russian Federation
organisation Analysis of the
‎2026/10/06
Threat actors used a vulnerable AMD Radeon Software driver (CVE-2023-20598) to escalate privileges and blind security-related processes, then deployed the LunexStealer malware through compromised websites using ClickFix-style Cloudflare verification checks.
organisation The Lunex
organisation CAPTCHA
organisation AMD
organisation ClickFix
organisation Cloudflare
organisation CVE-2023-20598
organisation Lunex
organisation AMD Radeon
infrastructure Windows
organisation Microsoft
organisation MSI
organisation LunexLoader
organisation User Account Control
organisation Lunex Uses
organisation Disable Security Monitoring and
organisation LunexStealer
organisation Chromium
organisation C2 Panel
organisation SQLite
organisation Native Messaging Host
organisation PDB
data_breach 2026 September
organisation BYOVD
organisation EDR
organisation Lunex Unmasked
data_breach 13,200 byte
organisation RAR
organisation Disable Security Monitoring and Steal Browser
organisation Google Chrome
organisation Microsoft Edge, Brave
organisation Opera GX
organisation NMH
organisation Chrome Secure Preferences
data_breach 524 MB write
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Microsoft Office
Affected Product
Metrics
data_breach
2,026
September
Metrics
data_breach
13,200
Byte
Metrics
data_breach
524
Mb Write