Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Lunex chain examined by Ontinue used a legitimate but vulnerable AMD driver associated with CVE-2023-20598. This method, known as Bring Your Own Vulnerable Driver, allowed the loader to access Windows kernel memory and disable monitoring callbacks used by endpoint-security products. | Following those instructions downloaded an MSI installer from an attacker-controlled server and installed Lunex Stealer.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Following those instructions downloaded an MSI installer from an attacker-controlled server and installed Lunex Stealer.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows information stealer distributed through fake Cloudflare verification prompts on more than 100 compromised Ukrainian websites. It steals browser passwords, authentication tokens, cookies, payment-card details, autofill information and cryptocurrency wallet data. Its command-and-control system supports additional instructions, file downloads, execution and remote access. Some infections deploy LunarAxe and NaiveMess for persistent access. A Lunex chain examined by Ontinue exploited a vulnerable AMD driver to disable endpoint-security monitoring; the article does not establish that this technique was used in the Ukrainian website campaign.
Information-stealing malware distributed to Ukrainian users through compromised websites displaying fake Cloudflare verification pages. Victims are tricked into running PowerShell commands through the ClickFix technique. Lunex steals credentials, authentication tokens and cryptocurrency wallet data and provides remote access. It can install malicious browser components whose access may persist after the main executable is removed. Researchers describe it as an actively developed malware-as-a-service platform sold to multiple independent criminal operators.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.