Back to Intelligence

Lunex Stealer BYOVD Chain, Operation Master AdaptixC2 Pipeline & PureRAT Japan Campaign: OTX Pulse Analysis — Enterprise Infostealer Detection Pack

SA
Security Arsenal Team
September 28, 2026
11 min read

This week's OTX pulse cluster paints a coherent picture of a maturing credential-theft economy: five distinct operations, all converging on the same monetization objective — harvested credentials, browser session data, and enterprise network access for resale or downstream fraud.

Lunex Stealer (AlienVault/Ontinue) represents the cutting edge of stealer tradecraft: a four-stage chain beginning with fake CAPTCHA pages targeting Ukrainian-speaking users, escalating to kernel-level defense evasion via Bring Your Own Vulnerable Driver (BYOVD) using AMD's vulnerable PDFWKRNL.sys (CVE-2023-20598). Once EDR visibility is blinded at the kernel level, LunexLoader deploys LunexStealer, which rips credentials from seven Chromium-based browsers using custom SQL queries against browser SQLite stores and abuses native messaging hosts for browser hijacking.

Operation Master (actor: masterblack, SOCRadar) is the industrial-scale counterpart: a multi-tiered intrusion and monetization pipeline that scanned 277.5 million addresses to curate 81 high-value targets across 16 countries and 7 industries. Initial access rides a Palo Alto GlobalProtect authentication bypass (CVE-2026-0257), supplemented by a broad exploit kit (CVE-2022-40684 FortiOS, CVE-2024-1086 Linux kernel, CVE-2021-4034 PwnKit, CVE-2020-1938 Ghostcat, CVE-2021-36260 Hikvision, CVE-2023-7028 GitLab). Post-exploitation uses the AdaptixC2 framework, DNS tunneling for C2, SQL injection with xp_cmdshell for database theft, OAuth device-code phishing, and an invoice-fraud monetization platform.

Kothamine Agent (Malwarebytes) is an undocumented 30+ command RAT distributed via malicious npm packages, evading network detection by tunneling C2 through Tailscale's tailcat — legitimate mesh-VPN infrastructure that blends with sanctioned traffic. Variants include browser data theft and camera/microphone capture.

The Stealer Factory (K7 Labs) is a Python-based MaaS builder lowering the barrier to entry: operators generate customized Nuitka/PyInstaller-compiled Windows stealers with anti-VM checks, XOR+Base64-obfuscated webhook exfiltration configuration, and automatic dependency installation. Expect a long tail of low-sophistication variants from this builder.

PureRAT/PureLogs Japan Campaign (ITOCHU) rounds out the set: Japanese and Korean-language phishing lures disguised as product-damage complaints deliver ZIP archives with double-extension executables, DLL sideloading, Donut shellcode loading, process hollowing, and — again — BYOVD for defense evasion, culminating in PureRAT and the PureLogs stealer.

Collective assessment: BYOVD is no longer an APT-exclusive technique — it appears in two of five pulses. Legitimate-infrastructure C2 (Tailscale, webhooks, DNS tunneling, native messaging hosts) is the dominant evasion pattern. Browser credential stores remain the primary target across all stealer families.

Threat Actor / Malware Profile

Lunex Stealer / LunexLoader / PDFWKRNL

  • Distribution: Fake CAPTCHA verification pages targeting Ukrainian-speaking users; social-engineered execution chain.
  • Payload behavior: Four-stage chain. Stage progression culminates in LunexStealer extracting credentials, cookies, and autofill data from seven Chromium-based browsers via custom SQL against Login Data / Web Data SQLite databases. Browser hijacking via Chrome native messaging host registration.
  • Anti-analysis / defense evasion: BYOVD — drops and loads the legitimately signed but vulnerable AMD driver PDFWKRNL.sys (CVE-2023-20598) to terminate or blind kernel-level security monitoring before payload deployment.
  • C2: Observed infrastructure includes 194.165.16.55 and 31.76.103.132.

Operation Master (masterblack) / AdaptixC2

  • Distribution / initial access: Mass scanning (277.5M IPs) → curated exploitation of perimeter appliances, led by GlobalProtect auth bypass CVE-2026-0257; supplementary exploits for FortiOS, Hikvision, Linux kernel, GitLab, and Tomcat AJP.
  • Payload behavior: AdaptixC2 beacons for hands-on control; SQL injection with xp_cmdshell to exfiltrate databases from 9+ MSSQL instances; OAuth device-code phishing for identity compromise; invoice-fraud platform for monetization.
  • C2: DNS tunneling for low-and-slow beaconing; C2 node 91.92.241.184.
  • Persistence: AdaptixC2 implant persistence plus valid-account abuse from phished OAuth tokens.

Kothamine Agent

  • Distribution: Malicious npm packages (supply-chain vector targeting developers/technology sector).
  • Payload behavior: 30+ remote commands — command execution, file manipulation, plugin/capability extension; browser data theft; camera and microphone recording in some variants.
  • C2: Encrypted C2 tunneled through Tailscale's tailcat utility, hiding inside legitimate WireGuard-based mesh VPN traffic.

Python MaaS Stealer Builder

  • Distribution: MaaS model — customers generate their own binaries; distribution varies by operator (phishing, cracks, malvertising).
  • Payload behavior: Browser data extraction, anti-VM checks, webhook-based exfiltration (Discord/Telegram-style) with XOR + Base64 encoded configuration.
  • Anti-analysis: Nuitka or PyInstaller compilation producing large, unpacked-looking executables that evade signature and some heuristic engines.

PureRAT / PureLogs (Japan campaign)

  • Distribution: Japanese/Korean phishing emails themed as product-damage complaints → fake document-sharing sites → ZIP archives with double-extension executables (e.g., .pdf.exe).
  • Payload behavior: DLL sideloading chains, Donut in-memory shellcode loader, process hollowing into legitimate processes; PureRAT for remote control, PureLogs for credential/log harvesting.
  • Anti-analysis: BYOVD driver deployment for EDR tampering; process hollowing to masquerade as trusted binaries.
  • C2: Infrastructure on 103.153.74.201, 103.179.188.236 and domains including baoquocgiavn.com, bayareakajabe.com, bartonaussies.com.

IOC Analysis

The 172 indicators across these pulses break down into four operational classes:

  • IPv4 addresses (194.165.16.55, 31.76.103.132, 91.92.241.184, 103.153.74.201, 103.179.188.236): C2 and staging infrastructure. Push to egress firewall/proxy block lists and retro-hunt 90 days of NetFlow/proxy logs. Note that stealer C2 churns fast — IP blocks are a snapshot control, not a durable one.
  • Domains (PureRAT campaign infrastructure): Block at DNS resolver (RPZ) and secure web gateway. ThePureRAT domains follow a disposable, thematically random registration pattern — alert on newly registered domains (<30 days) matching phishing lure context.
  • File hashes (MD5/SHA1/SHA256 for Lunex, Kothamine, Stealer Factory, PureRAT samples): Load into EDR blocklists and your TI platform (MISP, OpenCTI, or direct OTX integration via the API/SDK). SHA256 values are the reliable pivots; MD5/SHA1 are provided for legacy tool compatibility.
  • CVEs: This is the highest-value indicator class. CVE-2023-20598 (AMD driver — add PDFWKRNL.sys to your vulnerable-driver blocklist per Microsoft's recommended driver block rules), CVE-2026-0257 (GlobalProtect — patch/emergency mitigations immediately if applicable), CVE-2022-40684, CVE-2024-1086, CVE-2021-4034, CVE-2020-1938, CVE-2021-36260, CVE-2022-28368, CVE-2023-7028. Cross-reference against your attack surface management inventory — Operation Master is actively scanning for these.

Tooling: OTX indicators decode natively into MISP/STIX via the OTX DirectConnect API. For the Donut shellcode loader in the PureRAT chain, use donut-decryptor or Mandiant's speakeasy for emulation; XOR-encoded webhook configs in the Python stealers yield to CyberChef (XOR brute-force + Base64 recipe). Browser Login Data extraction attempts are best caught behaviorally — not by hash.

Detection Engineering

YAML
---
title: BYOVD Vulnerable AMD Driver Load - PDFWKRNL
id: 9f2a1b3e-7c4d-4e8a-b1f2-lunexbyovd0001
status: experimental
description: Detects load or creation of the vulnerable AMD PDFWKRNL.sys driver used by Lunex Stealer and PureRAT campaigns for BYOVD defense evasion (CVE-2023-20598)
author: Security Arsenal Threat Intelligence
date: 2026/09/28
references:
    - https://www.ontinue.com/resource/lunex-unmasked-a-new-information-stealer-deployed-through-byovd
logsource:
    category: driver_load
    product: windows
detection:
    selection_name:
        ImageLoaded|endswith: '\PDFWKRNL.sys'
    selection_hash:
        Hashes|contains:
            - '6e8b49cf70bf854e8c59c7d27cefa89406caf8978461190dabb86dafcd8554e1'
    selection_unsigned:
        Signed: 'false'
    condition: selection_name or selection_hash or (selection_name and selection_unsigned)
falsepositives:
    - Legitimate AMD software installations (rare on servers)
level: high
tags:
    - attack.defense_evasion
    - attack.t1068
    - attack.t1562.001
---
title: Chromium Browser Credential Database Access by Non-Browser Process
id: 1a4b7c2d-8e5f-4a9b-c2d3-stealersql00002
status: experimental
description: Detects non-browser processes accessing Chromium Login Data/Cookies SQLite stores - common to Lunex, PureLogs, and Python MaaS stealers
author: Security Arsenal Threat Intelligence
date: 2026/09/28
references:
    - https://www.ontinue.com/resource/lunex-unmasked-a-new-information-stealer-deployed-through-byovd
    - https://labs.k7computing.com/index.php/the-stealer-factory-unpacking-a-python-based-maas-infostealer-builder
logsource:
    category: file_access
    product: windows
detection:
    selection_files:
        TargetFilename|contains:
            - '\AppData\Local\Google\Chrome\User Data\'
            - '\AppData\Local\Microsoft\Edge\User Data\'
            - '\AppData\Local\BraveSoftware\Brave-Browser\User Data\'
            - '\AppData\Roaming\Opera Software\'
    selection_targets:
        TargetFilename|endswith:
            - '\Login Data'
            - '\Cookies'
            - '\Web Data'
            - '\Local State'
    filter_browsers:
        Image|endswith:
            - '\chrome.exe'
            - '\msedge.exe'
            - '\brave.exe'
            - '\opera.exe'
    condition: selection_files and selection_targets and not filter_browsers
falsepositives:
    - Legitimate password managers and backup software
level: high
tags:
    - attack.credential_access
    - attack.t1555.003
---
title: Tailscale Tailcat or DNS Tunneling C2 via Legitimate Infrastructure
id: 7d3e9f1a-2b6c-4d7e-a3f4-kothaminec200003
status: experimental
description: Detects execution of tailcat/tailscale by unauthorized processes (Kothamine Agent) and suspicious DNS query volume consistent with AdaptixC2 DNS tunneling
author: Security Arsenal Threat Intelligence
date: 2026/09/28
references:
    - https://www.malwarebytes.com/blog/threat-intel/2026/09/kothamine-malware-uses-tailscales-tailcat-to-evade-network-detection
    - https://socradar.io/blog/operation-master-intrusion-monetization-pipeline
logsource:
    category: process_creation
    product: windows
detection:
    selection_tailcat:
        Image|endswith:
            - '\tailcat.exe'
            - '\tailscaled.exe'
        ParentImage|endswith:
            - '\cmd.exe'
            - '\powershell.exe'
            - '\node.exe'
            - '\wscript.exe'
            - '\rundll32.exe'
    selection_double_ext:
        CommandLine|contains:
            - '.pdf.exe'
            - '.doc.exe'
            - '.xlsx.exe'
    selection_npm_child:
        ParentImage|endswith: '\node.exe'
        Image|endswith:
            - '\cmd.exe'
            - '\powershell.exe'
            - '\tailcat.exe'
    condition: 1 of selection_*
falsepositives:
    - Sanctioned Tailscale deployments - baseline and whitelist approved install paths
    - Developers running npm tooling
level: medium
tags:
    - attack.command_and_control
    - attack.t1101
    - attack.t1071.004
    - attack.t1219
KQL — Microsoft Sentinel / Defender
// Security Arsenal - Infostealer & C2 Infrastructure Hunt (Lunex / Operation Master / PureRAT / Kothamine)
// Hunt window: adjust as needed
let Lookback = 14d;
let C2IPs = dynamic(["194.165.16.55","31.76.103.132","91.92.241.184","103.153.74.201","103.179.188.236"]);
let BadDomains = dynamic(["baoquocgiavn.com","bayareakajabe.com","bartonaussies.com"]);
let BadHashes = dynamic([
  "6e8b49cf70bf854e8c59c7d27cefa89406caf8978461190dabb86dafcd8554e1",
  "ec4219a7ecf132c29080fbb20e4ab410c57faa85aeed7acade1eb15d905a6ee0",
  "74eca3973ad72a6ddc9397aff8250d9ee287211fc9a055d5ee290d01cf76a70c",
  "5ab36c116767eaae53a466fbc2dae7cfd608ed77721f65e83312037fbd57c946"]);
// 1) Network connections to known C2
let NetHits = DeviceNetworkEvents
| where Timestamp > ago(Lookback)
| where RemoteIP in~ (C2IPs) or RemoteUrl in~ (BadDomains)
| project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteIP, RemoteUrl, RemotePort;
// 2) Vulnerable driver / stealer hash execution
let FileHits = DeviceProcessEvents
| where Timestamp > ago(Lookback)
| where SHA256 in~ (BadHashes)
   or ProcessCommandLine has_any ("PDFWKRNL","tailcat","Login Data",".pdf.exe")
| project Timestamp, DeviceName, FileName, ProcessCommandLine, SHA256, InitiatingProcessFileName;
// 3) Browser credential store access by suspicious processes
let CredAccess = DeviceFileEvents
| where Timestamp > ago(Lookback)
| where FileName in~ ("Login Data","Cookies","Web Data","Local State")
| where FolderPath has_any ("\\Chrome\\User Data\\","\\Edge\\User Data\\","\\Brave-Browser\\")
| where not(InitiatingProcessFileName in~ ("chrome.exe","msedge.exe","brave.exe"))
| project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, FolderPath, FileName;
union NetHits, FileHits, CredAccess
| sort by Timestamp desc
PowerShell
# Security Arsenal - Lunex/PureRAT/Stealer-Factory IOC Hunt
# Run as Administrator on endpoints or via your RMM/EDR script module
$ErrorActionPreference = 'SilentlyContinue'
$Report = @()

# 1) Vulnerable BYOVD driver presence (Lunex / PureRAT - CVE-2023-20598)
$DriverPaths = @("$env:SystemRoot\System32\drivers\PDFWKRNL.sys", "$env:TEMP\PDFWKRNL.sys")
foreach ($p in $DriverPaths) {
    if (Test-Path $p) {
        $h = (Get-FileHash $p -Algorithm SHA256).Hash
        $Report += [PSCustomObject]@{Check='BYOVD Driver'; Finding=$p; Detail="SHA256: $h"}
    }
}
Get-CimInstance Win32_SystemDriver | Where-Object { $_.Name -match 'PDFWKRNL' } | ForEach-Object {
    $Report += [PSCustomObject]@{Check='Loaded Vuln Driver'; Finding=$_.Name; Detail=$_.PathName}
}

# 2) Chrome Native Messaging Host hijack artifacts (Lunex browser hijacking)
$NMH = 'HKLM:\SOFTWARE\Google\Chrome\NativeMessagingHosts','HKCU:\SOFTWARE\Google\Chrome\NativeMessagingHosts'
foreach ($key in $NMH) {
    Get-ChildItem $key | ForEach-Object {
        $manifest = (Get-ItemProperty $_.PSPath).'(default)'
        if ($manifest -and $manifest -notmatch 'Google|Microsoft') {
            $Report += [PSCustomObject]@{Check='Suspicious NativeMessagingHost'; Finding=$_.PSChildName; Detail=$manifest}
        }
    }
}

# 3) Unauthorized Tailscale/tailcat install (Kothamine C2 channel)
$tail = Get-Process tailscaled,tailscale -ErrorAction SilentlyContinue
if ($tail) { $Report += [PSCustomObject]@{Check='Tailscale Process Running'; Finding=$tail.Name -join ','; Detail='Verify against approved software inventory'} }
Get-ChildItem "$env:LOCALAPPDATA\Tailscale","$env:ProgramFiles\Tailscale" -ErrorAction SilentlyContinue | ForEach-Object {
    $Report += [PSCustomObject]@{Check='Tailscale Install'; Finding=$_.FullName; Detail='Confirm authorized deployment'}
}

# 4) Double-extension executables in user-writable dirs (PureRAT phishing ZIPs)
Get-ChildItem "$env:USERPROFILE\Downloads","$env:TEMP" -Recurse -Include *.pdf.exe,*.doc.exe,*.xlsx.exe -ErrorAction SilentlyContinue | ForEach-Object {
    $Report += [PSCustomObject]@{Check='Double-Extension Executable'; Finding=$_.FullName; Detail="Created: $($_.CreationTime)"}
}

# 5) Known C2 connections (established or recent)
$C2 = '194.165.16.55','31.76.103.132','91.92.241.184','103.153.74.201','103.179.188.236'
Get-NetTCPConnection -State Established | Where-Object { $C2 -contains $_.RemoteAddress } | ForEach-Object {
    $proc = (Get-Process -Id $_.OwningProcess).ProcessName
    $Report += [PSCustomObject]@{Check='ACTIVE C2 CONNECTION'; Finding=$_.RemoteAddress; Detail="Process: $proc (PID $($_.OwningProcess))"}
}

# 6) Known malware hashes in common staging locations
$BadHashes = '3f4c9025125027e307b7e52dd577303b','41ff3ecd1458b0bf86e1b4891636213e','b96d75a000367c200958089728fc5cb8','82699276b0f59a2304120a6baaf64a6b','429ed63ab3fbda8d22d0ac750ecfe8cc'
Get-ChildItem "$env:TEMP","$env:USERPROFILE\Downloads","$env:APPDATA" -Recurse -File -ErrorAction SilentlyContinue |
  Where-Object { $_.Length -lt 50MB } | ForEach-Object {
    if ($BadHashes -contains (Get-FileHash $_.FullName -Algorithm MD5).Hash.ToLower()) {
        $Report += [PSCustomObject]@{Check='KNOWN MALWARE HASH'; Finding=$_.FullName; Detail='Isolate host immediately'}
    }
  }

$Report | Format-Table -AutoSize
if (-not $Report) { Write-Host '[+] No indicators of compromise found.' -ForegroundColor Green }
else { Write-Host "[!] $($Report.Count) finding(s) - escalate to IR." -ForegroundColor Red }

Response Priorities

Immediate (0–4 hours):

  • Block all C2 IPs (194.165.16.55, 31.76.103.132, 91.92.241.184, 103.153.74.201, 103.179.188.236) and PureRAT domains at egress firewall, proxy, and DNS resolver.
  • Push the SHA256/MD5 hash sets to EDR blocklists; deploy the Sigma rules and run the KQL hunt across a 14–30 day lookback.
  • Verify PDFWKRNL.sys is on your vulnerable-driver blocklist (Microsoft VBS driver block rules or EDR equivalents) — two separate campaigns are weaponizing it.
  • Emergency-check exposure: Palo Alto GlobalProtect (CVE-2026-0257), FortiOS (CVE-2022-40684), GitLab (CVE-2023-7028) — Operation Master is actively scanning for these at internet scale.

24 hours:

  • All five pulses involve credential theft. If any endpoint hunt hits, treat all credentials stored in browsers on that host as compromised: force resets for domain accounts, revoke OAuth refresh tokens and active sessions (critical given Operation Master's OAuth device-code phishing), and invalidate web session cookies.
  • Audit Chrome native messaging host registrations fleet-wide via the PowerShell script.
  • Audit Tailscale installations against your approved software inventory — Kothamine hides C2 inside sanctioned-looking mesh VPN traffic.
  • Review MFA fatigue / device-code grant logs in Entra ID for anomalous OAuth consent.

1 week:

  • Patch or mitigate the full Operation Master CVE list; prioritize internet-facing appliances.
  • Enforce application control (WDAC/AppLocker) blocking unsigned drivers and executables in user-writable paths; block double-extension files at email gateway and web proxy.
  • Restrict browser credential storage risk: enable App-Bound Encryption where available, deploy EDR tamper protection for browser data paths, and move users to hardware-backed password managers.
  • Add npm package vetting to developer workstations (lockfiles, private registry proxying, typosquat detection) to close the Kothamine supply-chain vector.
  • Enhance DNS analytics for tunneling detection (query length/entropy/volume baselines) to counter AdaptixC2-style C2.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.