Zero News | A Fake "I'm Not a Robot" Check Steals Every Password in Your Browser: Lunex Stealer
Security firm Ontinue has uncovered Lunex, a new malware-as-a-service platform.
The attack starts with a fake Cloudflare "I'm not a robot" check on compromised websites.
One Command Is Enough
In this technique, known as ClickFix, the user is asked to run a command on their computer to complete the verification.
That single action is enough to install the malware.
Would your employees paste a command into their computer just to prove they are human?
Blinding the Security Software
Lunex loads an old but digitally signed AMD Radeon driver (PDFWKRNL.sys) that carries the CVE-2023-20598 vulnerability.
With this BYOVD (Bring Your Own Vulnerable Driver) technique, it gains kernel-level access and blinds antivirus and EDR tools without shutting them down. The security software appears to be running, but it no longer sees anything.

What Gets Stolen
Lunex steals saved passwords, session cookies and crypto wallets from Chrome, Edge, Brave, Opera, Opera GX, Vivaldi and Yandex Browser.
With stolen session cookies, attackers can log in without the password or MFA. A persistent browser component keeps running even after the file is deleted or the PC is restarted.
Recommended Actions
If a website asks you to paste and run something in Win+R, PowerShell or a command prompt to verify yourself, it is an attack; make sure users know this.
Enable Microsoft's Vulnerable Driver Blocklist and HVCI (Memory Integrity) on all devices.
Do not save passwords in the browser; use a corporate password manager and prefer passkeys for critical accounts.
Remove local admin rights, and restrict and monitor PowerShell and MSI execution with application control.
After a suspected infection, end all active sessions and revoke session tokens, not just passwords.
For more information, contact our experts at info@zerosecond.ae.
Zero Second | Zero News – Weekly cybersecurity briefing.
Zero News, prepared by Zero Second.





















Comments