Skip to main content

Command Palette

Search for a command to run...

Cyber ​​Security Warning: Lunex Stealer Malware Abuses AMD Drivers to Steal Business Accounts

Updated
•12 min read•View as Markdown
Cyber ​​Security Warning: Lunex Stealer Malware Abuses AMD Drivers to Steal Business Accounts

Overview

Have you ever thought that attackers do not need to write complex lines of code to bypass EDR signatures? Instead, they apply the BYOVD (Bring Your Own Vulnerable Driver>) technique - carrying a genuine AMD driver but with memory design flaws. Through just a few sophisticated IOCTL commands, Kernel Security Callbacks (where EDR relies on to capture behavior) are silently removed in just a few milliseconds without causing a system crash (BSOD).

Hidden behind this dangerous campaign is an ominous combination of the ShinyHunters group's extensive PeopleSoft exploitation campaign, the new generation C2 infrastructure AdaptixC2 (Operation Master), and Lunex Stealer malware that specializes in scanning browser credentials and cryptocurrency wallets.

How can an attacker abuse AMD drivers to overwrite Kernel memory? Why are EDR processes completely silent when the malware drains accounts? And how to trace this attack chain in a corporate environment? The detailed answer will be decoded in the technical analysis section below.

Event Timeline

Below is the progression of the attack chain from the initial intrusion until the malware completes data collection and extraction:

Stage Technical Action Notes & Detection Indicators
T0: Initial Access Exploit a vulnerability in an Internet-facing PeopleSoft application or send a phishing email containing a loader. Exploitation activity has been associated with the ShinyHunters threat group.
T+1h: C2 Deployment Execute an AdaptixC2 Beacon (Operation Master) and establish an encrypted command-and-control channel. Unusual HTTPS connections to AdaptixC2 infrastructure.
T+2h: BYOVD Staging Drop a legitimately signed AMD driver containing a kernel memory vulnerability into a system directory. A request to create a new Driver Service with NT AUTHORITY\SYSTEM privileges is observed.
T+2h 05m: Defenses Impairment Send IOCTL commands to the AMD driver to overwrite kernel callback mechanisms such as ObRegisterCallbacks and PsSetCreateProcessNotifyRoutine. EDR/AV processes stop receiving telemetry from kernel memory.
T+2h 10m: Payload Execution Launch the Lunex Stealer process in user mode. EDR hooks are no longer available to prevent access to sensitive files.
T+2h 15m: Data Exfiltration Collect SQLite databases from Chrome/Edge/Firefox, DPAPI encryption keys, and cryptocurrency wallet data; compress and upload the data to the C2 server. A sudden increase in outbound traffic to the C2 IP address is observed.

Threat Actor Analysis: ShinyHunters Cyber ​​Crime Group

Overview & Operation History

ShinyHunters is one of the most notorious and active cybercrime groups (Cybercrime Group) from around mid-2020 until now. This group is famous for its large-scale data theft attacks (Mass Data Breach) targeting technology, telecommunications, e-commerce and financial corporations globally.

Unlike APT groups with political intelligence motives (Cyber ​​Espionage), ShinyHunters' main motive is financial gain through business extortion (Data Extortion) or selling databases containing millions of user information on underground forums such as BreachForums or RaidForums.

Typical Techniques & Methods of Combat (TTPs)

ShinyHunters constantly evolves its attack methods to optimize the effectiveness of wide-area penetration:

  • Mass Exploitation: The team focuses on hunting and developing exploit code (PoC/Exploit) for vulnerabilities in Internet-facing enterprise management applications (Public-Facing Enterprise Applications) such as Oracle PeopleSoft, Salesforce, or Cloud/SaaS management interfaces.

  • Credential & API Keys Abuse: Collect leaked admin accounts from previous infostealer rounds or scan source code repositories (GitHub, GitLab) to search for leaked API keys and AWS credentials.

  • Specialize the malware supply chain: Clearly separate the Initial Access stage (initial break-in) from the Post-Exploitation stage. The group actively cooperates or acquires modern C2 infrastructure (such as AdaptixC2 in the Operation Master campaign) and new generation information-stealing malware lines (Lunex Stealer).

Detailed Analysis of Attack Flows & Combat Techniques

Step 1: Initial Exploitation & Break-in via Oracle PeopleSoft (ShinyHunters)

It all started with the enterprise's Oracle PeopleSoft financial and human resource management systems facing the Internet. The notorious hacker group ShinyHunters automatically scans on a large scale to search for servers that have not been updated with security patches.

  • How to break in: The attacker sends exploit packets (exploit payload) into exposed PeopleSoft service ports. Once successfully exploited, they gain remote code execution (RCE - Remote Code Execution) permissions on the server.

  • Goal: Create an "initial foothold" (Beachhead) and drop a Loader-like executable file into the system without user action.

Step 2: Build an anonymous control channel – AdaptixC2 Infrastructure (Operation Master)

After successfully breaking in, Loader immediately activated AdaptixC2 - a new generation C2 (Command and Control) framework that is very popular among cybercriminals. The variant used in this campaign belongs to the operational infrastructure codenamed Operation Master.

  • Mechanism of action: AdaptixC2 creates an encrypted reverse connection channel (Beacon) via HTTPS protocol to the attacker's C2 server (master-ops-c2[.]com).

  • Effects: This C2 channel helps attackers maintain remote control, receive orders to execute system commands, and bypass regular firewalls by disguising traffic as legitimate HTTPS Web access.

Step 3: Kernel-level EDR paralysis – BYOVD technique abuses AMD Drivers

This is the most dangerous technical step of the entire campaign. To prevent EDR/Antivirus solutions from detecting and blocking data theft at a later step, attackers must "blind" EDR from the operating system kernel (Kernel) level.

To do this without the system blocking the digital signature, they use the BYOVD (Bring Your Own Vulnerable Driver) technique:

  • Loading the "Original" Driver is vulnerable

    • The attacker carries a Driver file released by AMD itself and validly digitally signed by Microsoft (but this version has a memory design vulnerability). They register this driver as a Windows service (AmdDrvService). Because the driver has a genuine digital signature, the Windows operating system allows it to be loaded directly into the Kernel without any doubt.
  • Abusing IOCTL instructions to read/write Kernel RAM

    • From user-mode, the malware sends IOCTL (Input/Output Control) control codes to the AMD Driver. Flaws in AMD drivers allow malicious code to read and write directly to any Kernel memory area.
  • "Remove" EDR name from Kernel Callbacks array

    • EDR solutions monitor the system by registering their names into Kernel function pointer arrays (like ObRegisterCallbacks or PsSetCreateProcessNotifyRoutine). Every time there is a process reading a file or creating a new process, the Kernel will call EDR to check.
  • The malicious code searches for EDR function pointers in Kernel memory.

  • They use memory writes to overwrite the EDR function pointer to NULL or insert a stop instruction (RET).

  • Result: The EDR process on the interface still says "Active", but at the Kernel level, EDR has been completely "deaf and blind" - no longer receiving any warning signals. It all went smoothly without causing a blue screen (BSOD) issue.

Step 4: Launch Lunex Stealer – Clear Crypto Accounts & Wallets

Once the EDR defense line has been silently disabled, the new Lunex Stealer malware is officially released to execute under User-mode. At this point, Lunex Stealer can freely read all sensitive files on the computer without worrying about being blocked by EDR.

The malware scanned three main groups of data assets:

  1. Browser login information (Chrome, Edge, Firefox, Brave):

    • Find SQLite database files such as Login Data, Web Data, Cookies.

    • Use the Windows DPAPI function (CryptUnprotectData) to decrypt the Master Key and wipe out all Saved Passwords and session Cookies.

  2. Cryptocurrency Wallets:

    • Read data from browser extensions such as MetaMask, Coinbase Wallet, Phantom, Trust Wallet.

    • Find and collect Desktop wallet archive files (Exodus, Atomic, Electrum).

  3. System data & Token:

    • Collect Discord Token, Telegram Session, SSH Keys, VPN configuration and computer hardware information.

Step 5: Extract data (Exfiltration) to C2

After collection, Lunex Stealer compresses all stolen data into encrypted temporary files (for example, lunex_tmp.dat located in the %TEMP% folder).

Finally, through the AdaptixC2 connection channel established in Step 2, the malware sends these data files back to the C2 server via disguised HTTP POST requests. After successful extraction, the malware automatically deletes temporary files on the hard disk to erase traces of forensic analysis (Anti-forensics).

IOCs & Artifacts

File Hash SHA-256

  • 38e90affe37342ee36917cdc535fe9bf04589afa8430eb8d1ba1016adcfc1878

  • bf14cd6c3328ebd08e940478b5d1da04e9e5aa576d045d41950bf4f1e2456dd8

  • 6e8b49cf70bf854e8c59c7d27cefa89406caf8978461190dabb86dafcd8554e1

  • e9745f1791b2a6374711756e89c7bf2864e52f9ff467974f2f7bdc667f9f28c6

  • 06f434695f93d7fd11eeff71358ff69fed79d310a66d993bbcc4ff979c117c90

  • 94bb7481aff840736fe6396fa270aa68ad24bc76e38a1e9fe899ce4356ccfa1e

File Hash MD5

  • 1f250eb486571d99bc1e4d760e37a554

  • 348cabe85c8bb40e690ab873ab94acac

  • b96d75a000367c200958089728fc5cb8

  • ae5450f32bcb533c5b592c77a7861553

IP C2

  • 95.179.159[.]159

  • 151.80.21[.]203

  • 195.26.224[.]69

  • 109.238.86[.]45

  • 217.77.15[.]181

  • 130.12.180[.]187

  • 62.60.226[.]103

  • 86.109.75[.]162

  • 87.120.104[.]148

  • 37.187.140[.]177

  • 193.178.159[.]128

  • 193.178.158[.]61

  • 87.120.104[.]147

  • 84.32.149[.]103

  • 194.165.16[.]55

  • 109.238.86[.]48

  • 109.238.86[.]112

  • 109.238.87[.]205

  • 176.53.159[.]98

  • 103.101.85[.]123

  • 185.207.15[.]147

  • 91.92.34[.]243

  • 94.158.247[.]238

  • 132.243.235[.]195

  • 94.154.32[.]21

  • 31.76.103[.]132

  • 78.17.74[.]164

  • 45.151.106[.]252

URL Malicious

  • hxxps://uasputnik[.]com/elita.msi

  • hxxp://107.175.82[.]242:9000/wilow/psychedeliclove.exe

  • hxxps://msdl.microsoft[.]com/download/symbols/ntkrnlmp.pdb//ntkrnlmp.pdb

Malicious Domain

  • uasputnik[.]com

  • api-goo-drivehosting[.]com

  • account-sams-club[.]com

  • teamwork-recover-password[.]com

  • namshi-uae[.]com

  • whatsappbusineses[.]com

  • ibraq-perfumes[.]com

MITRE ATT&CK Mapping

Tactic Technique ID Technique Name Description of Application in the Campaign
Initial Access T1190 Exploit Public-Facing Application Exploitation of vulnerabilities in the PeopleSoft application by the ShinyHunters group.
Execution T1059.003 Command and Scripting Interpreter: Windows Command Shell Execution of scripts to download the loader and register the driver service.
Persistence T1543.003 Create or Modify System Process: Windows Service Creation of a Windows Service to load the vulnerable AMD driver into the kernel.
Privilege Escalation T1068 Exploitation for Privilege Escalation Abuse of AMD Driver IOCTL functionality to obtain arbitrary kernel memory write capabilities.
Defense Evasion T1562.001 Impair Defenses: Disable or Modify Tools Removal/overwriting of kernel security callbacks to disable EDR telemetry.
Credential Access T1555.003 Credentials from Password Stores: Credentials from Web Browsers Theft of password databases and cookies from Chrome, Edge, and Firefox.
Credential Access T1003 OS Credential Dumping Decryption and extraction of stored credential data using Windows DPAPI.
Command & Control T1071.001 Application Layer Protocol: Web Protocols Maintaining an encrypted communication channel through AdaptixC2 infrastructure (Operation Master).
Exfiltration T1041 Exfiltration Over C2 Channel Exfiltration of compressed credential-related files to the C2 server over the established C2 channel.

Expert Comments

BYOVD technology is not new, but the appearance of new generation popular hardware drivers such as the AMD driver in the Lunex Stealer campaign marks a notable shift for cybercriminal groups. In the past, attackers often abused older generation drivers such as RTCore64.sys (Micro-Star International) or gdrv.sys (GIGABYTE). Because these old drivers have been blacklisted by most security solutions, attackers are forced to hunt down and exploit newer drivers from major original equipment manufacturers (OEMs) to bypass the initial digital signature checking mechanisms.

In addition, the combination of ShinyHunters (a group specializing in exploiting enterprise application vulnerabilities), AdaptixC2 (professional control infrastructure) and Lunex Stealer demonstrates the trend of commercialization and deep collaboration in the cybercrime supply chain. Attackers no longer write the entire tool from scratch but assemble the most optimal solutions at each stage: Exploit → Control → Disable EDR → Data collection.

For the business environment in Vietnam: Through monitoring work at SOC FPT IS, we realize that risks are especially great for organizations in the Finance - Banking sector, State agencies and large enterprises that are operating complex ERP systems (such as Oracle PeopleSoft) towards the Internet. Many businesses, despite being equipped with expensive EDR, turn off the HVCI (Hypervisor-Protected Code Integrity) feature or have not updated the Microsoft Vulnerable Driver Blocklist due to concerns about affecting system performance or compatibility with old software. This is the deadly "blind spot" that Lunex Stealer's BYOVD technology is thoroughly exploiting.

Recommendations for Remediation & Prevention

To protect systems against the Lunex Stealer attack chain and BYOVD techniques, organizations need to immediately deploy measures according to the following roadmap:

Urgent (0-24 hours)

  • Check and Block IOCs: Immediately update all IOC indicators (Hashes, IPs, Domains) into the Firewall, Proxy, EDR and SIEM systems to detect and prevent C2 connections of AdaptixC2.

  • Enable Driver Blocklist: Enable the Microsoft Vulnerable Driver Blocklist feature on all Windows workstations and servers using the PowerShell command (requires Administrator rights):

    • Get-CimInstance -ClassName Win32_DeviceGuard -Namespace root\Microsoft\Windows\DeviceGuard

    • Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\CI\Config" -Name "VulnerableDriverBlocklistEnable" -Value 1 -Type DWord

Short term (1-7 days)

  • Configure Windows Defender Application Control (WDAC): Build a strict WDAC policy, only allowing loading system drivers that are in a carefully censored list; Prevent the loading of AMD/OEM drivers that are exposed to reported vulnerabilities.

  • Patch PeopleSoft vulnerabilities: Review all Oracle PeopleSoft servers facing the Internet, apply the latest security patches from the manufacturer to eliminate the initial intrusion path of the ShinyHunters group.

  • Check for unknown services: Scan for newly initialized Windows services (Services) running under SYSTEM that are involved in loading unknown .sys files.

Long term

  • Deploy HVCI (Virtualization-Based Security) architecture: Ensure VBS and HVCI are enabled by default on all enterprise devices. HVCI will prevent Kernel memory modifications even if the process has administrative rights or abuses a legitimate driver.

  • Switch to Behavioral Detection: Configure EDR to monitor unusual behavior such as: User-mode process calls unusual IOCTL to hardware driver, process accesses the browser's sensitive data storage folder that is not the browser application itself.

References

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

Lunex Unmasked: A New Information Stealer Deployed Through BYOVD

Lunex Stealer BYOVD Chain + AdaptixC2 'Operation Master' + ShinyHunters PeopleSoft Mass Exploitation: OTX Pulse Analysis — Enterprise Detection Pack | Security Arsenal | Security Arsenal

More from this blog

F

FPT IS Security

1031 posts

Dedicated to providing insightful articles on cybersecurity threat intelligence, aimed at empowering individuals and organizations to navigate the digital landscape safely.