“We assess with confidence that this activity originates from a financially motivated, CIS-aligned threat actor operating through the Lunex platform,” says Rhys Downing, Threat Researcher at Ontinue.
Lunex Malware-as-a-Service platform and alleged origins
Ontinue Cyber Defence Centre published an analysis linking a new infostealer campaign to the Lunex Malware-as-a-Service platform. The researchers say the tooling appears to be developed by a Russian-speaking developer or team and then sold to cybercriminal customers. Ontinue’s write-up also asserts this is the first public, in-depth binary analysis of Lunex operational tooling.
Four-stage attack chain: from false CAPTCHA to C2 agent
Ontinue reverse-engineered a four-stage chain that begins with a false CAPTCHA page and culminates in a fully featured command-and-control (C2) agent running on the victim host. The chain deploys a stealer that exfiltrates data and extracts material from cryptocurrency wallets. Persistence and remote file-system access are established via a PowerShell-based Native Messaging Host installed inside the target’s browser.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageBring Your Own Vulnerable Driver (BYOVD) and EDR blindness
Before the final stealer runs, the attack executes a Bring Your Own Vulnerable Driver (BYOVD) sequence that disables kernel-level monitoring. Ontinue notes that while BYOVD is not a novel concept, it is uncommon to see it executed prior to a final-stage payload. The practical effect, the researchers say, is to allow the final payload to “run after disabling callbacks from multiple endpoint security products.”
John Bambenek, President at Bambenek Consulting, highlighted a related detection opportunity: “Tools like these almost always try to enumerate running processes to find security tools that can detect them. I have found that it is a strong EDR signal to look for this relatively easy to spot behavior to block the executable early in the attack lifecycle so remediation can be done. No legitimate tool looks for competing security products.”
Exploiting browser trust, vendor certificates, and OT/IoT risk
John Gallagher, Vice President at Viakoo, framed the attack as one that “exploits trust” by abusing built-in platform mechanisms rather than breaking encryption or guessing passwords. Gallagher describes the chain this way: a valid vendor certificate can get code into kernel space, Windows Driver Signature Enforcement can be abused to make the OS accept a vulnerable driver, built-in browser APIs grant persistence, and administrative browser credentials can unlock downstream network access.
Gallagher also flagged the potential reach of a browser-based persistence mechanism: “Many OT/IoT systems use browser-based consoles which can extend this attack vector way beyond just IT systems.” That detail links the campaign’s browser persistence technique to a broader set of networked devices and operational environments.
What this means for technologists, procurement leaders, and end users
- Technologists and security teams: Ontinue recommends focusing detection on stages that occur before kernel-level monitoring is disabled. Bambenek’s observation points defenders toward watching for process-enumeration behavior as an early, high-fidelity EDR signal to block execution prior to later stages.
- Procurement and infrastructure owners for OT/IoT systems: Gallagher’s warning about browser-based consoles expanding the blast radius means procurement leaders should inventory where administrative access is delivered via browsers and consider the added risk if browser persistence is achieved on those endpoints.
- End users and administrators: the campaign’s initial lure—a false CAPTCHA page—underscores that seemingly benign web interactions can initiate sophisticated, multi-stage compromises that ultimately target cryptocurrency wallets and file-system access.
Ontinue’s analysis makes two linked, concrete points: the tooling is saleable through a criminalized platform (Lunex) and the attack sequence deliberately removes the defenders’ ability to see the final stages. The combination of a BYOVD-disabling step, browser-based persistence, and wallet extraction is a specific operational profile defenders can and should treat as distinct from single-stage commodity stealers. Whether defenders will shift detection further left in the attack chain — to the false CAPTCHA lure and the process-enumeration signals Bambenek highlights — is the immediate, testable next step implied by the research.
Read the original Ontinue analysis at https://www.securitymagazine.com/articles/102601-new-russian-infostealer-targeting-ukrainian-users




