Threat Brief — 2026-09-26 — Lunex MaaS unmasked, AMD driver abused
Executive Summary
The most significant new development today is the identification of the Psychedelic Stealer campaign as part of a broader malware-as-a-service platform called Lunex, which abuses a legitimate AMD driver to disable security monitoring before exfiltrating browser credentials. This reframes what was initially reported as a single-stealer incident into a structured MaaS operation. No other fresh findings in this cycle introduce genuinely new developments beyond previously covered stories.
Top items
- Lunex MaaS platform identified behind Psychedelic Stealer; abuses AMD driver to evade detection. Ontinue's analysis reveals that the Psychedelic Stealer malware — previously reported being distributed via compromised Ukrainian websites using fake Cloudflare ClickFix verification prompts — is actually part of a wider malware-as-a-service operation called Lunex. The malware loads a legitimate AMD driver to disable security monitoring tools before harvesting browser credentials. This is a genuine development of a story first reported 2026-09-24 by The Hacker News, elevating the threat from a single-campaign stealer to a reusable MaaS platform with defensive-evasion capabilities. (src: The Hacker News)
Themes
Bring-your-own-licensed-driver (BYOVD) remains a favoured evasion technique. Lunex's abuse of a legitimate AMD driver to blind security monitoring joins a well-established pattern of threat actors using signed kernel drivers to disable EDR and monitoring tools. The technique persists because it exploits trust in legitimately signed components rather than software vulnerabilities.
