New Russian Infostealer Targeting Ukrainian Users

A four-stage attack chain linked to the Lunex Malware-as-a-Service platform has been identified and reverse-engineered by the Ontinue Cyber Defence Centre. It appears to be targeting Ukrainians.
“We assess with confidence that this activity originates from a financially motivated, CIS-aligned threat actor operating through the Lunex platform,” says Rhys Downing, Threat Researcher at Ontinue. “To our knowledge, this article presents the first public, in-depth binary analysis of the operational tooling associated with Lunex.”
The research also believes this created by a Russian-speaking developer/team and is sold to cybercriminals.
The chain starts with a false CAPTCHA page and concludes with a deployed, fully featured C2 agent. The stealer exfiltrates data, extracts from cryptocurrency wallets, and secures persistent remote filesystem access via a PowerShell-based Native Messaging Host inside of the target’s browser.
However, before the stealer is deployed, a Bring Your Own Vulnerable Driver (BYOVD) chain is run, disabling kernel-level monitoring. While utilizing a BYOVD isn’t unusual, it isn’t often seen before a final-stage payload. This enables the final payload to “run after disabling callbacks from multiple endpoint security products.”
John Bambenek, President at Bambenek Consulting, comments, “Tools like these almost always try to enumerate running processes to find security tools that can detect them. I have found that it is a strong EDR signal to look for this relatively easy to spot behavior to block the executable early in the attack lifecycle so remediation can be done. No legitimate tool looks for competing security products.”
John Gallagher, Vice President at Viakoo, adds, “Like many attack vectors, exploiting trust is the foundation of this entire attack. The whole ‘bring your own vulnerable driver’ approach relies on abusing Window’s Driver Signature Enforcement to have the OS blindly trust the driver.
“Exploiting the browser is a path to expanding the blast radius of the attack. Many OT/IoT systems use browser-based consoles which can extend this attack vector way beyond just IT systems.
“The attack succeeds not by breaking encryption or guessing passwords, but by turning trusted components against the system: a valid vendor certificate gets them into the kernel, built-in browser APIs grant them persistence, and administrative browser credentials give them the keys to downstream networks.”
The researcher asserts that for defenders, detection must target stages before EDR blindness occurs.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!








