Researchers have documented a multistage Windows malware chain in which Lunex Stealer abuses a legitimately signed but vulnerable AMD kernel driver before collecting browser and cryptocurrency data. The technique is an example of bring your own vulnerable driver, or BYOVD, in which attackers load a trusted driver whose known flaw provides kernel-level capabilities.
The driver is used to weaken monitoring
The chain begins with a fake verification page and a malicious installer. Its loader uses the vulnerable PDFWKRNL.sys driver associated with CVE-2023-20598 to interfere with callbacks used by security products. The products can remain running while losing visibility into activity that follows. The final stealer targets credentials, session cookies and wallet information from several Chromium-based browsers and can add a native-messaging component for persistence and remote file operations.
AMD published its original bulletin for the driver vulnerability in 2023. The current campaign matters because it shows how older signed-driver flaws can be combined with newer malware delivery and persistence techniques.
Driver controls need operational testing
Defenders should inventory vulnerable drivers, apply vendor updates, review driver-loading telemetry and test whether Microsoft’s vulnerable-driver blocklist is active in their actual Windows configuration. Browser credential theft also increases the value of phishing-resistant authentication and rapid session revocation. SectechMedia tracks related developments in its cybersecurity coverage.

Leave a Reply