New Russian Infostealer: A Four-Stage Cyberattack Targeting Ukrainian Users
New Russian Infostealer Targets Ukrainian Users in Sophisticated Four-Stage Cyberattack
A newly identified Russian-linked infostealer malware has been reverse-engineered by cybersecurity researchers after it was found targeting Ukrainian users through a deceptive four-stage attack chain tied to the Lunex Malware-as-a-Service platform.
The discovery marks what researchers describe as the first public in-depth binary analysis of operational tooling associated with the Lunex platform. The attack is notable for its sophistication and its deliberate use of trusted system components to evade detection — raising serious concerns for cybersecurity defenders across both IT and operational technology environments.
To understand the broader landscape of threats like this one, it helps to familiarise yourself with the different types of malware and how they operate — infostealers represent one of the fastest-growing and most commercially weaponised categories.
How the Attack Unfolds
The Ontinue Cyber Defence Centre identified and reverse-engineered the attack chain, which begins with a false CAPTCHA page and ends with a fully deployed command-and-control (C2) agent operating deep inside the victim's system.
Rhys Downing, Threat Researcher at Ontinue, stated clearly where the threat originates. "We assess with confidence that this activity originates from a financially motivated CIS-aligned threat actor operating through the Lunex platform," Downing said. "To our knowledge, this article presents the first public in-depth binary analysis of the operational tooling associated with Lunex."
Researchers also believe the malware was created by a Russian-speaking developer or team and is being sold to cybercriminals through the Lunex platform — a Malware-as-a-Service model that lowers the barrier for bad actors to deploy highly capable tools without building them from scratch.
Once inside a victim's system, the stealer performs three primary functions:
- It exfiltrates sensitive data
- It extracts credentials from cryptocurrency wallets
- It secures persistent remote filesystem access through a PowerShell-based Native Messaging Host embedded inside the target's browser
This combination of data theft and persistent access makes the Lunex-linked tooling particularly dangerous. Unlike opportunistic malware that executes a single payload and exits, this attack is designed for prolonged, stealthy occupation of the victim's environment.
The Initial Deception: False CAPTCHA as Entry Point
The attack begins with a social engineering lure — a fake CAPTCHA page designed to trick users into executing malicious commands on their own machines. This technique, increasingly common in financially motivated campaigns, exploits the routine expectation that CAPTCHA verification is a normal, benign interaction. By the time a user realises something is wrong, the first stage of the attack chain has already completed. Attacks that begin with deceptive web pages like this share characteristics with common phishing attack methods used to steal credentials and execute malware.
A Dangerous Technique Deployed Before the Final Payload
BYOVD: Blinding Defences Before Striking
What makes this attack particularly alarming is the use of a Bring Your Own Vulnerable Driver (BYOVD) chain — deployed before the final-stage payload is executed. While BYOVD techniques are not unheard of in cyberattacks, this placement is unusual and deliberate.
By running the BYOVD chain earlier in the process, the attackers disable kernel-level monitoring. This allows the final payload to run after disabling callbacks from multiple endpoint security products — effectively blinding the tools designed to stop it.
John Bambenek, President at Bambenek Consulting, explained why this behaviour should itself serve as a detection signal. "Tools like these almost always try to enumerate running processes to find security tools that can detect them," Bambenek said. "I have found that it is a strong EDR signal to look for this relatively easy to spot behavior to block the executable early in the attack lifecycle so remediation can be done. No legitimate tool looks for competing security products."
That observation is critical for defenders. Identifying malware that scans for security software — before it disables those tools — may be the most reliable window to intervene.
Why Early-Stage Detection Is Non-Negotiable
Ontinue researchers assert that detection must target stages before EDR blindness occurs. Once the BYOVD chain has executed and security callbacks are disabled, the window for automated detection narrows significantly. Early-stage intervention is not just preferable — it is essential.
Organisations should consider whether their current security stack provides visibility into pre-execution behaviours, including process enumeration and driver loading activity. Relying solely on endpoint detection tools that can themselves be disabled is an architectural vulnerability, not just a configuration gap.
Exploiting Trust at Every Layer
How the Attack Weaponises Legitimate Components
John Gallagher, Vice President at Viakoo, offered a broader perspective on why this attack is so effective. Rather than brute-forcing its way through encryption or guessing passwords, the malware turns trusted components against the very systems they are meant to protect.
"Like many attack vectors, exploiting trust is the foundation of this entire attack," Gallagher said. "The whole 'bring your own vulnerable driver' approach relies on abusing Windows' Driver Signature Enforcement to have the OS blindly trust the driver."
Gallagher also highlighted the expanded risk this poses beyond traditional IT environments. "Exploiting the browser is a path to expanding the blast radius of the attack. Many OT/IoT systems use browser-based consoles which can extend this attack vector way beyond just IT systems."
He summarised the attack's core mechanism with sharp precision. "The attack succeeds not by breaking encryption or guessing passwords but by turning trusted components against the system: a valid vendor certificate gets them into the kernel, built-in browser APIs grant them persistence, and administrative browser credentials give them the keys to downstream networks."
This is a textbook example of what cybersecurity professionals call a supply-chain-of-trust attack — where each level of penetration opens access to a deeper and more dangerous layer. A valid vendor certificate opens the kernel. Browser APIs establish persistence. Administrative credentials unlock downstream networks. Each stage is legitimate in isolation; combined, they form a complete and largely invisible compromise.
The OT and IoT Blind Spot
The risk to operational technology and IoT environments deserves particular emphasis. Many industrial control systems, building management platforms, and network infrastructure components are managed through browser-based consoles. If an attacker achieves persistent access through a browser-based Native Messaging Host, the reach of that access is not confined to the workstation — it potentially extends to every system that workstation's browser has ever authenticated against.
Security teams in critical infrastructure, manufacturing, utilities, and healthcare should treat this attack pattern as directly relevant to their environments, not just a concern for enterprise IT.
What Defenders Should Do Now
The emergence of this infostealer underscores the growing commodification of sophisticated cyberweapons through Malware-as-a-Service platforms. As tools once reserved for nation-state actors become accessible to financially motivated criminals, the line between espionage and cybercrime continues to blur. For organisations that want to assess their current exposure and response capability, reviewing free malware removal and detection tools available to security teams is a practical starting point for shoring up endpoint defences.
Security teams monitoring environments with Ukrainian user bases or CIS-region exposure should treat any process that enumerates running security software as a high-priority threat signal. Organisations relying on browser-based OT and IoT consoles should assess their exposure to Native Messaging Host abuse. And defenders at every level should assume that endpoint security tools alone — without layered pre-execution detection — may not be sufficient to stop attacks designed specifically to silence them.
For further technical context on the Lunex platform and the broader Malware-as-a-Service ecosystem, the CISA malware threat advisories provide regularly updated guidance on emerging threats relevant to both public and private sector defenders.