On September 24, 2026, Ontinue published an analysis linking a Lunex-associated information-stealing chain targeting Ukrainian-speaking users to AMD’s PDFWKRNL.sys driver. Ontinue says the chain uses the vulnerable driver to impair kernel-level security monitoring before deploying a stealer that targets browser credentials, session data and cryptocurrency-wallet information.
How PDFWKRNL.sys fits into the reported Lunex chain
The attack uses a technique called bring your own vulnerable driver, or BYOVD: an attacker brings a legitimate but vulnerable driver onto a system and abuses its access to interfere with security protections.
Ontinue describes a four-stage chain that starts with a fake CAPTCHA page prompting a victim to run an installer. A loader then uses the Windows CMSTPLUA COM object in a privilege-escalation sequence and loads PDFWKRNL.sys before downloading the stealer. Ontinue reports that the driver stage zeroes selected kernel callbacks. Security products may remain running, but their monitoring is impaired.
What the stealer reportedly targets
Ontinue says the stealer seeks credentials, session data and browsing information from seven Chromium-based browsers: Google Chrome, Microsoft Edge, Brave, Yandex Browser, Opera, Opera GX and Vivaldi. It also targets five desktop cryptocurrency wallets—Bitcoin Core, Litecoin, Exodus, Atomic Wallet and Electrum—and four browser-extension wallets: MetaMask, MetaMask Legacy, OKX Wallet and SafePal Wallet.
The reported access can extend beyond stolen browser and wallet data. Ontinue describes three persistence routes: a Registry Run key, a hidden scheduled task and a browser Native Messaging Host, a component that lets a browser communicate with a local program. The PowerShell-backed host supports remote filesystem operations, including listing, reading, writing and downloading files, as well as running programs. Ontinue says it can remain after the stealer binary is deleted, a system reboots or a browser restarts.
Ontinue also identified 28 unique Lunex panels across 13 countries during its September 2026 investigation.
What AMD says about CVE-2023-20598
AMD’s security bulletin describes CVE-2023-20598 as an improper privilege-management vulnerability in its Radeon Graphics kernel driver. AMD says an authenticated attacker could craft an IOCTL request to gain control over hardware ports or physical addresses, potentially enabling arbitrary code execution.
AMD’s bulletin, first published October 16, 2023, and revised January 4, 2024, lists Adrenalin Edition 23.9.2 for specified Radeon RX 5000, RX 6000 and RX 7000 graphics cards. It also lists PRO Edition 23.Q4 versions for specified PRO cards and applicable client-processor platforms.
What Ontinue’s HVCI and blocklist test found
In its September 24 analysis, Ontinue reported that its validated test loaded the specific PDFWKRNL.sys variant used in the chain despite HVCI and Microsoft’s then-current Vulnerable Driver Blocklist. The finding applies to the tested variant and conditions; it does not establish how every driver version or Windows configuration behaves.