Back to Intelligence

Lunex Stealer BYOVD Chain + AdaptixC2 'Operation Master' + ShinyHunters PeopleSoft Mass Exploitation: OTX Pulse Analysis — Enterprise Detection Pack

SA
Security Arsenal Team
September 28, 2026
12 min read

Three concurrent threat pulses published to AlienVault OTX on 2026-09-28 paint a picture of an actively hostile landscape for perimeter appliances, browser credential stores, and enterprise ERP platforms. This briefing synthesizes the pulses into detection engineering, IOC operationalization guidance, and prioritized response actions for enterprise SOC teams.


Threat Summary

Three distinct but complementary threat activity clusters were reported:

1. Lunex Stealer (BYOVD delivery, Ukrainian targeting). A four-stage infection chain begins with fake CAPTCHA pages served to Ukrainian-speaking users. Victims are socially engineered into executing a loader (LunexLoader) that drops and abuses PDFWKRNL.sys — an AMD driver vulnerable to CVE-2023-20598 — in a Bring Your Own Vulnerable Driver (BYOVD) attack to blind kernel-level security monitoring (EDR/AV callback removal) before deploying LunexStealer. The stealer targets seven Chromium-based browsers, extracts credentials via custom SQL queries against browser SQLite stores (Login Data, Cookies, Web Data), and leverages a malicious native messaging host for browser-hijacking persistence and continued credential siphoning.

2. Operation Master (actor: masterblack, AdaptixC2). A multi-tiered intrusion-and-monetization pipeline that scanned 277.5 million IP addresses to curate 81 high-value targets across Energy, Technology, Finance, Education, Healthcare, Retail, and Telecommunications in 16 countries (US, UK, Canada, Brazil, Mexico, much of Western Europe, Qatar, and Latin America). Initial access leverages a Palo Alto GlobalProtect authentication bypass (CVE-2026-0257) alongside a deep exploitation arsenal (CVE-2022-40684 Fortinet auth bypass, CVE-2024-1086 Linux kernel privilege escalation, CVE-2021-4034 PwnKit, CVE-2020-1938 Ghostcat, CVE-2021-36260, CVE-2022-28368, CVE-2023-7028 GitLab account takeover). Post-exploitation includes SQL injection with xp_cmdshell for database theft (9+ instances), the AdaptixC2 post-exploitation framework, DNS tunneling for covert C2, OAuth device-code phishing, and a multi-tenant invoice fraud / BEC monetization platform.

3. ShinyHunters / UNC6240 — Oracle PeopleSoft mass exploitation (CVE-2026-35273). The prolific extortion group has resumed global mass exploitation of Oracle PeopleSoft across Education, Technology, Healthcare, Agriculture, Transportation, and Government. Notably, they bypassed WAF rules by URL-encoding a single character in the request path to reach the vulnerable Environment Management component. Post-exploitation tooling includes the SIDEEYE backdoor, Neo-reGeorg web shell tunneling, and MeshAgent for persistent remote access — consistent with their data-theft-and-extortion playbook.

Collective assessment: Organizations face simultaneous pressure at three layers — the endpoint (kernel-level EDR tampering), the network edge (VPN/auth bypass with industrial-scale scanning), and the application tier (ERP exploitation with trivial WAF evasion). Unpatched edge appliances and PeopleSoft instances should be treated as presumed targeted.


Threat Actor / Malware Profile

LunexStealer / LunexLoader / PDFWKRNL

  • Distribution: Fake CAPTCHA verification pages targeting Ukrainian-language users; victim is lured into running an initial dropper.
  • Payload behavior: Four-stage chain culminating in an information stealer that enumerates and extracts credentials, cookies, and autofill data from seven Chromium-based browsers using custom SQL against browser SQLite databases.
  • BYOVD / anti-analysis: Deploys AMD's vulnerable PDFWKRNL.sys (CVE-2023-20598) to gain kernel access and disable or uninstall kernel-level security monitoring — a direct EDR-blinding technique. Expect driver load events for unexpected .sys files in user-writable paths.
  • Persistence: Installs a native messaging host in Chromium-based browsers, enabling browser hijacking and survival across browser credential clears.
  • C2: Exfiltration infrastructure observed at 194.165.16.55 and 31.76.103.132.

masterblack / AdaptixC2

  • Distribution / initial access: GlobalProtect authentication bypass (CVE-2026-0257), Fortinet auth bypass (CVE-2022-40684), Ghostcat (CVE-2020-1938), GitLab reset flaw (CVE-2023-7028), plus privilege escalation via CVE-2024-1086 and CVE-2021-4034 (PwnKit).
  • Payload behavior: Database theft via SQL injection abusing xp_cmdshell; lateral movement and hands-on activity via AdaptixC2 beacons.
  • C2 communication: DNS tunneling for low-and-slow exfiltration and beaconing; AdaptixC2 infrastructure at 91.92.241.184.
  • Monetization: Multi-tenant phishing infrastructure, OAuth device-code phishing for token theft, and an invoice fraud platform — indicating financially motivated monetization of enterprise access rather than pure espionage.

UNC6240 / ShinyHunters (SIDEEYE, Neo-reGeorg, MeshAgent)

  • Distribution: Mass exploitation of Oracle PeopleSoft CVE-2026-35273; WAF bypass achieved by URL-encoding one character in the request path to reach the Environment Management component.
  • Payload behavior: Deployment of the SIDEEYE backdoor, Neo-reGeorg (HTTP-tunneling web shell enabling internal pivot through the compromised web server), and MeshAgent (legitimate RMM tool abused for durable remote access).
  • Persistence: Web shells on PeopleSoft web tier plus MeshAgent service installation — dual persistence across web and OS layers.
  • Objective: Bulk data theft from PeopleSoft (HR/finance/student records) followed by extortion — the classic ShinyHunters model.

IOC Analysis

Indicator composition across the pulses:

TypeExamplesOperationalization
IPv4 (C2 / infra)194.165.16.55, 31.76.103.132, 91.92.241.184, 104.219.234.138Block at egress firewall/proxy; retro-hunt NetFlow, DNS query logs, and proxy logs for 90 days; add to EDR network containment lists
Domainsazurenetfiles.netDNS sinkhole; hunt DNS logs and TLS SNI in proxy/Zeek logs; the name mimics legitimate Azure file services — inspect rather than assume benign
CVEsCVE-2026-0257 (GlobalProtect), CVE-2026-35273 (PeopleSoft), CVE-2023-20598 (AMD driver), CVE-2024-1086, CVE-2021-4034, CVE-2022-40684, CVE-2020-1938, CVE-2021-36260, CVE-2022-28368, CVE-2023-7028Feed into vulnerability management as emergency patch/verify items; correlate with asset inventory to find exposed GlobalProtect portals and PeopleSoft instances
File hashes (MD5/SHA1/SHA256)LunexStealer chain hashes; SIDEEYE/MeshAgent SHA256sImport into EDR block lists (SHA256 preferred — MD5s are collision-prone); sweep with your EDR's hash-search; note hash-based detection decays fast against repacked stealers — prioritize behavioral rules

Tooling guidance: Normalize indicators into STIX/TAXII if your TIP supports it (OTX exports natively). Use Zeek/Suricata for DNS tunneling detection on the masterblack infrastructure, Sysmon + driver-load event (Event ID 6) for BYOVD detection, and WAF log review for URL-encoded anomalous paths against PeopleSoft endpoints.


Detection Engineering

YAML
---
title: BYOVD Vulnerable Driver Load - PDFWKRNL (Lunex Stealer Chain)
id: 9e3b1a7c-2f4d-4e8a-b1c5-7d6e9f0a1b2c
status: experimental
description: Detects loading of the vulnerable AMD PDFWKRNL.sys driver abused by LunexLoader for BYOVD EDR-blinding (CVE-2023-20598), or driver loads from user-writable paths
author: Security Arsenal
date: 2026/09/28
references:
    - https://www.ontinue.com/resource/lunex-unmasked-a-new-information-stealer-deployed-through-byovd
logsource:
    category: driver_load
    product: windows
detection:
    selection_name:
        ImageLoaded|endswith: '\PDFWKRNL.sys'
    selection_path:
        ImageLoaded|contains:
            - '\Users\'
            - '\Temp\'
            - '\AppData\'
            - '\ProgramData\'
        ImageLoaded|endswith: '.sys'
    condition: selection_name or selection_path
falsepositives:
    - Legitimate AMD software updates loading signed drivers from Program Files (path filter excludes these)
level: high
tags:
    - attack.defense_evasion
    - attack.t1068
    - attack.t1562.001
---
title: Chromium Browser Credential Store Access by Non-Browser Process (LunexStealer)
id: 4a8c2d1e-6b7f-4c3a-9e2d-1f0b8a5c3d7e
status: experimental
description: Detects non-browser processes accessing Chromium credential SQLite databases (Login Data, Cookies, Web Data), consistent with LunexStealer custom SQL credential extraction across seven Chromium browsers
author: Security Arsenal
date: 2026/09/28
references:
    - https://www.ontinue.com/resource/lunex-unmasked-a-new-information-stealer-deployed-through-byovd
logsource:
    category: file_event
    product: windows
detection:
    selection_target:
        TargetFilename|contains:
            - '\User Data\Default\Login Data'
            - '\User Data\Default\Cookies'
            - '\User Data\Default\Network\Cookies'
            - '\User Data\Default\Web Data'
    filter_browsers:
        Image|contains:
            - '\chrome.exe'
            - '\msedge.exe'
            - '\brave.exe'
            - '\opera.exe'
            - '\vivaldi.exe'
    condition: selection_target and not filter_browsers
falsepositives:
    - Legitimate password managers and backup agents; whitelist by signer and path
level: high
tags:
    - attack.credential_access
    - attack.t1555.003
    - attack.t1539
---
title: PeopleSoft WAF-Bypass Exploitation and AdaptixC2/DNS-Tunnel Indicators (CVE-2026-35273 / Operation Master)
id: 7f1e9a3b-5c2d-4a8e-b6d4-0c9e2f7a4b1d
status: experimental
description: Detects URL-encoded PeopleSoft Environment Management access attempts characteristic of UNC6240/ShinyHunters WAF bypass, and high-entropy long-label DNS queries consistent with AdaptixC2 DNS tunneling
author: Security Arsenal
date: 2026/09/28
references:
    - https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft
    - https://socradar.io/blog/operation-master-intrusion-monetization-pipeline
logsource:
    category: webserver
detection:
    selection_peoplesoft_encoded:
        c-uri|contains:
            - '%2e'
            - '%2f'
            - '%5c'
            - '%25'
        cs-uri-stem|contains:
            - 'emf'
            - 'EnvironmentManagement'
            - 'PSEMHUB'
    selection_dns_tunnel:
        - 'azurenetfiles.net'
    condition: 1 of selection_*
falsepositives:
    - Some reverse proxies normalize encoded paths before logging; verify log source behavior
level: critical
tags:
    - attack.initial_access
    - attack.t1190
    - attack.command_and_control
    - attack.t1071.004
KQL — Microsoft Sentinel / Defender
// Security Arsenal — OTX 2026-09-28 Combined Hunt
// Lunex BYOVD driver loads, credential-store access, AdaptixC2/ShinyHunters C2,
// OAuth device-code phishing sign-ins, and xp_cmdshell database theft
let Lookback = 14d;
let C2IPs = dynamic(["194.165.16.55", "31.76.103.132", "91.92.241.184", "104.219.234.138"]);
let C2Domains = dynamic(["azurenetfiles.net"]);
let NetworkHits =
    DeviceNetworkEvents
    | where TimeGenerated > ago(Lookback)
    | where RemoteIP in (C2IPs) or RemoteUrl has_any (C2Domains)
    | project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteIP, RemoteUrl, RemotePort
    | extend Hunt = "OTX C2 Contact";
let DriverLoads =
    DeviceEvents
    | where TimeGenerated > ago(Lookback)
    | where ActionType == "DriverLoad" or (FileName endswith ".sys" and FolderPath has_any ("\\Users\\", "\\Temp\\", "\\AppData\\", "\\ProgramData\\"))
    | where FileName =~ "PDFWKRNL.sys" or FolderPath has_any ("\\Users\\", "\\Temp\\", "\\AppData\\")
    | project TimeGenerated, DeviceName, FileName, FolderPath, InitiatingProcessFileName, SHA256
    | extend Hunt = "BYOVD Driver Load";
let CredStoreAccess =
    DeviceFileEvents
    | where TimeGenerated > ago(Lookback)
    | where FolderPath has_any ("\\User Data\\Default\\Login Data", "\\User Data\\Default\\Cookies", "\\User Data\\Default\\Network\\Cookies", "\\User Data\\Default\\Web Data")
    | where not(InitiatingProcessFileName has_any ("chrome.exe", "msedge.exe", "brave.exe", "opera.exe", "vivaldi.exe"))
    | project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, FolderPath
    | extend Hunt = "Browser Credential Store Access";
let XpCmdshell =
    DeviceProcessEvents
    | where TimeGenerated > ago(Lookback)
    | where ProcessCommandLine has_any ("xp_cmdshell", "sp_configure", "Ole Automation") and FileName has_any ("sqlservr.exe", "sqlcmd.exe", "osql.exe")
    | project TimeGenerated, DeviceName, FileName, ProcessCommandLine, AccountName
    | extend Hunt = "SQL Injection / xp_cmdshell Abuse";
union NetworkHits, DriverLoads, CredStoreAccess, XpCmdshell
| sort by TimeGenerated desc
PowerShell
# Security Arsenal — OTX 2026-09-28 Host IOC Hunt
# LunexStealer (BYOVD + native messaging host) | AdaptixC2 | SIDEEYE/MeshAgent artifacts
$ErrorActionPreference = 'SilentlyContinue'
Write-Host "=== OTX Pulse Hunt: Lunex / masterblack / ShinyHunters ===" -ForegroundColor Cyan

# 1. Known malicious hashes from OTX pulses (SHA256 / MD5 sample set)
$BadHashes = @(
  '6e8b49cf70bf854e8c59c7d27cefa89406caf8978461190dabb86dafcd8554e1',
  '2bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7',
  '3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3',
  '419c571ee38b7e7266d130c4b6bbc4dd0ef44d6e5f3bc02cc2cf73b762f07c86',
  '48b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494',
  'ba14419beb2ec0bb94cab6298c14d7fb3e1d819366fe378290c0c2a4d97f7e07'
)
$BadMd5 = @('3f4c9025125027e307b7e52dd577303b','41ff3ecd1458b0bf86e1b4891636213e','b96d75a000367c200958089728fc5cb8')

Write-Host "[1] Scanning user-writable paths for malicious hashes..." -ForegroundColor Yellow
$SearchPaths = @("$env:TEMP", "$env:LOCALAPPDATA", "$env:APPDATA", "C:\ProgramData", "C:\Users\Public")
foreach ($p in $SearchPaths) {
  Get-ChildItem -Path $p -Recurse -File -ErrorAction SilentlyContinue | ForEach-Object {
    $sha = (Get-FileHash $_.FullName -Algorithm SHA256).Hash.ToLower()
    if ($BadHashes -contains $sha) { Write-Host "  [HIT-SHA256] $($_.FullName)" -ForegroundColor Red }
  }
}

# 2. BYOVD artifact: vulnerable AMD driver outside legitimate locations
Write-Host "[2] Hunting PDFWKRNL.sys (BYOVD, CVE-2023-20598) in non-standard paths..." -ForegroundColor Yellow
Get-ChildItem -Path "C:\Users","C:\ProgramData","C:\Windows\Temp" -Recurse -Filter "PDFWKRNL.sys" -ErrorAction SilentlyContinue |
  ForEach-Object { Write-Host "  [HIT-BYOVD] $($_.FullName)" -ForegroundColor Red }

# 3. Lunex persistence: rogue Chromium native messaging hosts
Write-Host "[3] Checking Chromium native messaging host registrations..." -ForegroundColor Yellow
$NMHKeys = @(
  'HKLM:\SOFTWARE\Google\Chrome\NativeMessagingHosts',
  'HKCU:\SOFTWARE\Google\Chrome\NativeMessagingHosts',
  'HKLM:\SOFTWARE\Microsoft\Edge\NativeMessagingHosts',
  'HKCU:\SOFTWARE\Microsoft\Edge\NativeMessagingHosts',
  'HKCU:\SOFTWARE\BraveSoftware\Brave\NativeMessagingHosts'
)
foreach ($k in $NMHKeys) {
  if (Test-Path $k) {
    Get-ChildItem $k | ForEach-Object {
      $manifest = (Get-ItemProperty $_.PSPath).'(default)'
      Write-Host "  [NMH] $($_.PSChildName) -> $manifest (verify legitimacy)" -ForegroundColor Magenta
    }
  }
}

# 4. MeshAgent / suspicious RMM persistence (ShinyHunters post-exploitation)
Write-Host "[4] Checking for MeshAgent service and suspicious Run keys..." -ForegroundColor Yellow
Get-Service | Where-Object { $_.Name -match 'mesh|MeshAgent' } |
  ForEach-Object { Write-Host "  [HIT-MESH] Service: $($_.Name) Status: $($_.Status)" -ForegroundColor Red }
@('HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run','HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run') |
  ForEach-Object {
    Get-ItemProperty $_ | ForEach-Object {
      $_.PSObject.Properties | Where-Object { $_.Value -match 'mesh|regeorg|sideeye|adaptix' } |
        ForEach-Object { Write-Host "  [HIT-RUNKEY] $($_.Name): $($_.Value)" -ForegroundColor Red }
    }
  }

# 5. Active/recent connections to OTX C2 indicators
Write-Host "[5] Checking network connections to known C2 infrastructure..." -ForegroundColor Yellow
$C2 = @('194.165.16.55','31.76.103.132','91.92.241.184','104.219.234.138')
Get-NetTCPConnection | Where-Object { $C2 -contains $_.RemoteAddress } |
  ForEach-Object {
    $proc = (Get-Process -Id $_.OwningProcess).ProcessName
    Write-Host "  [HIT-C2] $($_.RemoteAddress):$($_.RemotePort) State:$($_.State) Process:$proc (PID $($_.OwningProcess))" -ForegroundColor Red
  }
Resolve-DnsName "azurenetfiles.net" -ErrorAction SilentlyContinue |
  ForEach-Object { Write-Host "  [HIT-DNS] azurenetfiles.net resolves to $($_.IPAddress) — investigate" -ForegroundColor Red }

# 6. PeopleSoft web shell artifacts (if run on a PeopleSoft web tier)
Write-Host "[6] Checking common web roots for Neo-reGeorg / SIDEEYE web shells..." -ForegroundColor Yellow
$WebRoots = @('C:\inetpub\wwwroot','C:\psoft','D:\psoft')
foreach ($root in $WebRoots) {
  Get-ChildItem $root -Recurse -Include "tunnel*.jsp","*.jspx","*.aspx","*.ashx" -ErrorAction SilentlyContinue |
    Select-String -Pattern 'reGeorg|Neo-reGeorg|SIDEEYE|Socket|InetSocketAddress' -List |
    ForEach-Object { Write-Host "  [HIT-WEBSHELL] $($_.Path)" -ForegroundColor Red }
}

Write-Host "=== Hunt complete. Escalate any [HIT] findings to IR immediately. ===" -ForegroundColor Cyan

Response Priorities

Immediate (0–4 hours)

  • Block all network IOCs at egress firewall, proxy, and DNS layers: 194.165.16.55, 31.76.103.132, 91.92.241.184, 104.219.234.138, and azurenetfiles.net. Retro-hunt proxy/DNS/NetFlow logs for the past 90 days.
  • Import all file hashes into EDR block lists and sweep the fleet.
  • Audit PeopleSoft exposure: identify internet-facing PeopleSoft instances, review web logs for URL-encoded path anomalies targeting Environment Management endpoints, and hunt for web shells and MeshAgent services on those hosts.
  • Verify GlobalProtect patch status against CVE-2026-0257 on every PAN-OS edge device; if unpatched and internet-facing, treat as potentially compromised and check for AdaptixC2 beaconing and DNS tunneling.
  • Hunt for PDFWKRNL.sys loads from user-writable paths and non-browser access to Chromium credential stores using the detections above.

24 Hours

  • Credential reset campaign: LunexStealer and OAuth device-code phishing mean browser-stored credentials, session cookies, and OAuth tokens may be compromised. Force password resets and revoke all active sessions/refresh tokens for users on any host with a hunt hit; prioritize Ukrainian-speaking user populations and anyone who interacted with CAPTCHA-gated downloads.
  • Review Microsoft Entra ID / identity provider sign-in logs for device-code flow authentication anomalies (unfamiliar client IDs, unusual geographies, token grants without interactive login).
  • Review PeopleSoft application audit logs for bulk export/query activity consistent with pre-extortion data staging; check database audit trails for xp_cmdshell enablement on SQL Server instances.
  • Enable Microsoft's vulnerable driver blocklist (HVCI/WDAC) fleet-wide to neuter the CVE-2023-20598 BYOVD vector.

1 Week

  • Architecture hardening: Move PeopleSoft behind authenticated reverse proxy or VPN-only access; deploy strict URL-normalization rules on the WAF (decode-then-inspect, reject encoded path separators) to close the single-character encoding bypass class.
  • Segment SQL Server instances so xp_cmdshell is disabled by policy and alert on any sp_configure change; restrict database service accounts from OS command execution.
  • Deploy DNS egress controls (internal resolvers only, query-length/entropy alerting) to break DNS tunneling C2 channels like those used by masterblack.
  • Implement application control (WDAC/AppLocker) blocking unsigned drivers and executables in user-writable directories; inventory and restrict native messaging host registrations via browser enterprise policy.
  • Tabletop a combined stealer + extortion scenario: credential theft at the endpoint, ERP data theft at the application tier, and invoice fraud monetization — all three are represented in this pulse set.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.