Russia’s Hybrid Warfare: Understanding Lunex Malware as a Strategic Threat to Your Endpoints
Russia's Hybrid War Reaches Your Endpoints: Kremlin Doctrine and Criminal Malware Converge
A sophisticated malware platform with deep Russian fingerprints is actively targeting users across 13 countries — and new research suggests it is part of a broader Kremlin-backed hybrid warfare campaign that security teams can no longer afford to treat as a geopolitical abstraction.
Two reports published on September 24, 2026 — one from Recorded Future's Insikt Group and one from the Ontinue Cyber Defense Center — arrived within hours of each other and tell the same story from opposite ends of the telescope. Read together, they deliver an uncomfortable message: the headlines about drones over European airports and the malware on your organization's endpoints are branches of the same tree.
Russia's New Generation Warfare Is No Longer a Theory
Insikt Group's September 24th assessment documents how Russia has dramatically escalated its hybrid warfare campaign across Europe since its full-scale invasion of Ukraine in February 2022. The doctrine driving this campaign has a name — New Generation Warfare, or NGW — and its intellectual roots stretch back more than a decade.
The concept was articulated most clearly by Valeriy Gerasimov, Chief of the General Staff of the Russian Armed Forces, in a now-famous 2013 essay. "The very rules of war have changed," Gerasimov wrote. "The role of nonmilitary means of achieving political and strategic goals has grown and, in many cases, they have exceeded the power of force of weapons in their effectiveness."
NGW does not involve troops crossing borders or bombs falling on capitals. Instead, it deploys a complex kit of psychological, cyber, and physical tactics designed to test defenses, degrade critical infrastructure, and sow fear — while maintaining plausible deniability. Security professionals who study advanced persistent threats and state-sponsored attack campaigns will recognise this pattern immediately: patient, layered, and deliberately obscured attribution.
The Evidence Is Not Speculative
Airspace incursions have surged: researchers tracked 30 suspected NATO airspace violations between September 2025 and January 2026 alone — compared to just 23 across the entire March 2022 to August 2025 window. Poland and Romania have been the most frequently targeted countries, though violations have also reached Germany, the UK, Denmark, and Norway.
Physical sabotage is accelerating at an alarming rate. Insikt Group observed a four-fold increase in physical sabotage operations between 2023 and 2024, with 2025 holding at that elevated level. On August 4, 2026, an explosive quadcopter struck the wing of an Antonov An-124 cargo aircraft near its fuel tank at Leipzig Airport in Germany — what Insikt Group describes as the first instance in Europe of a sabotage drone carrying military-grade explosives near critical infrastructure. The German government publicly attributed the plot to Russia on September 1st after police recovered drones loaded with military-grade hexogen explosives.
What the Forecasts Actually Mean for Your Organization
Insikt Group's forecast is stark: Russia is likely to escalate NGW tactics over the next two years. Europe-based public and private sector entities are at very high risk of physical and cyber sabotage. Critical infrastructure operators face the highest exposure — with potential consequences including data loss, physical damage to facilities, and injury or death of personnel.
This is no longer a threat category that belongs exclusively in foreign policy briefings. The convergence of physical and cyber operations means that risk teams, CISOs, and security operations centers need to incorporate geopolitical threat intelligence into their operational planning — not treat it as background context for someone else to act on.
Meet Lunex: The Malware-as-a-Service Platform With Moscow's Fingerprints
While Insikt Group mapped the strategic picture, Ontinue's Cyber Defense Center published what it describes as the first in-depth binary analysis of Lunex — a malware-as-a-service platform whose connection to the geopolitical campaign is, in Ontinue's own assessment, hard to miss.
The campaign Ontinue reverse engineered targeted Ukrainian-speaking users through a fake CAPTCHA lure. The attack unfolds across four stages, beginning with a convincing fake verification page and culminating in the deployment of a fully featured command-and-control agent. The stealer binary was compiled on September 12, 2026 — just two days before the incident — with supporting infrastructure provisioned shortly beforehand, indicating active and ongoing development.
Understanding why this matters at the endpoint level requires appreciating why endpoint security is critical to your organization's overall defense posture — because Lunex is specifically engineered to dismantle those defenses before they can respond.
A Four-Stage Attack Chain Built for Stealth
What sets Lunex apart is the sophistication stacked at every stage of the attack chain.
The delivery mechanism instructs victims to run an msiexec command that silently installs a package presenting itself as "Vertification" by "Internal Software" — a deliberate misspelling matching a Ukrainian word in the lure. The installer requires no administrator privileges and triggers no UAC prompt. Before dropping its payload, the loader runs a Bring Your Own Vulnerable Driver chain using AMD's PDFWKRNL.sys — exploiting CVE-2023-20598 — to disable kernel-level security monitoring.
Ontinue flags this sequencing as unusual: BYOVD techniques are not uncommon, but deploying one before an information stealer rather than before ransomware is a meaningful tactical choice. It suggests the priority here is not destruction — it is silent, sustained access.
Rather than crudely killing security processes, the loader downloads Windows kernel debugging symbols directly from Microsoft's official Symbol Server to resolve exact kernel offsets, then uses the vulnerable driver to zero out callback entries from a 20-entry blocklist of security products. Notably, 45% of that blocklist targets Russian and CIS antivirus tools including Kaspersky and Dr.Web — consistent with a commercial platform designed for broad geographic applicability rather than a state-sponsored tool targeting only Western organizations.
Ontinue's testing confirmed that neither HVCI nor Microsoft's current Vulnerable Driver Blocklist prevents this specific PDFWKRNL.sys variant from loading — a gap that persists despite the driver hash being catalogued in the LOLDrivers project since March 2026.
The Persistence Mechanism Defenders Are Missing
The persistence mechanism deserves particular attention from defenders. The stealer establishes remote filesystem access through a PowerShell-based Chrome Native Messaging Host. This backdoor survives stealer binary deletion, system reboots, and browser restarts.
An incident responder who removes the stealer executable but fails to audit Native Messaging Host registrations leaves the attacker with full, persistent filesystem access through the browser. This single oversight has the potential to render an entire incident response engagement meaningless — the threat actor simply waits out the investigation and resumes access once the team stands down.
The Russian Fingerprints and a Rapidly Growing Criminal Supply Chain
Ontinue assesses with confidence that Lunex was developed by a Russian-speaking developer or team and is sold to multiple independent criminal operators. The evidence is layered and specific:
- The panel frontend contains over 150 Russian-language UI strings loaded as the default locale
- A placeholder in the browser-spoofing configuration uses "ya.ru" — Yandex Russia's homepage — as the default target domain, a reference natural only to a Russian-speaking developer
- Six of the 28 identified Lunex panels are hosted on UFO Technologies in Krasnogorsk, a satellite city of Moscow
Scale, Growth, and the Criminal Supply Chain Behind It
The platform is also growing fast. First documented by OSINT researcher Luke Wilkinson at BlueTeamCoolTeam in June 2026 — when six active panels were identified across five countries — Lunex had expanded to 28 panels across 13 countries by the time of Ontinue's internet-wide scan.
This is not a lone operator running a side hustle. It is a criminal supply chain with multiple stealer codebases written in Rust, C, and .NET connecting to the same panel architecture — scaled, maintained, and apparently thriving. The distinction between traditional endpoint protection tools and modern threats of this nature is increasingly stark; organizations still relying on legacy solutions should assess the critical differences between antivirus software and modern endpoint protection platforms to understand where gaps exist.
Three Actions Security Teams Should Take Now
Security teams reviewing these findings should act on three immediate priorities:
- Audit Chrome Native Messaging Host registrations on all endpoints as part of any incident response workflow — not just stealer binary removal. The persistence backdoor survives everything else.
- Verify whether your organization's EDR appears on Lunex's 20-entry blocklist and test whether your current kernel protections prevent the
PDFWKRNL.sysvariant from loading. Assume nothing until tested. - Treat geopolitical threat intelligence as operationally relevant input for your own risk modeling — particularly assessments about Russian NGW escalation. These are not background briefings for policymakers. They describe the environment your endpoints operate in.
The separation between geopolitical threat reporting and endpoint security operations is a structural blind spot that adversaries are actively exploiting. The Insikt Group and Ontinue reports, arriving on the same day from entirely different research angles, make that convergence impossible to dismiss.
The SecureWorld Dallas conference on October 8 will address threats of this nature. Security professionals looking to engage directly with researchers on hybrid warfare and endpoint defense can register at the SecureWorld Events page.