A sophisticated malware campaign targeting Ukrainian-speaking users has been linked to a broader malware-as-a-service platform known as Lunex. The operation begins with compromised legitimate websites and fake Cloudflare-style verification pages before eventually installing an information stealer capable of collecting browser credentials, cryptocurrency wallet data, session cookies, and other sensitive information.
Security researchers at Ontinue describe the infection as a four-stage attack chain built around social engineering, privilege escalation, security evasion, credential theft, and persistent remote access. What makes the campaign particularly interesting is its use of a legitimate but vulnerable AMD driver to interfere with security software before the final stealer payload is deployed.
Psychedelic Stealer Is Part of the Larger Lunex Platform
The malware was initially documented under the name Psychedelic Stealer, but researchers now say it represents one component of the wider Lunex malware-as-a-service ecosystem.
According to Ontinue, "Psychedelic" refers to the malware file actually executed on an infected device, while Lunex is the underlying criminal platform being developed and distributed to multiple operators. This explains why both LunexStealer and Psychedelic Stealer appear in reporting around the same campaign.
The MaaS model is significant because it means the malware does not necessarily belong to one single attacker. Instead, access to the platform can potentially be sold or provided to multiple criminal groups, allowing the same tooling and infrastructure to appear across unrelated campaigns.
The Attack Starts With Fake Cloudflare Verification
Victims are initially exposed through compromised legitimate websites. Researchers previously identified affected sites belonging to businesses including a hair-treatment clinic, specialist bookseller, scale-model manufacturer, psychological facility, automotive retailer, and tool retailer.
Attackers inject malicious content into those websites and display a fake CAPTCHA or Cloudflare verification prompt. This technique follows the increasingly common ClickFix approach, where users are persuaded to perform actions they believe are required to prove they are human or resolve a browser issue.
Instead, the instructions ultimately lead to execution of malicious content. In the Lunex campaign, victims are directed toward bogus MSI installers that begin the next stages of the infection.
LunexLoader Attempts to Bypass Windows Security Controls
The malicious installer deploys a loader researchers call LunexLoader. Its job is to prepare the Windows system for the final information stealer while avoiding or weakening built-in security controls.
One of its techniques involves bypassing User Account Control, or UAC, through the CMSTPLUA COM object. This allows the malware to gain additional privileges without relying on the more obvious privilege-escalation methods defenders may already be monitoring.
Once elevated access has been established, the malware moves into one of the more unusual parts of the attack: Bring Your Own Vulnerable Driver.
A Vulnerable AMD Driver Is Used to Blind Security Products
Lunex takes advantage of a legitimate AMD Radeon kernel driver named PDFWKRNL.sys, which is affected by CVE-2023-20598.
This is an example of the Bring Your Own Vulnerable Driver, or BYOVD, technique. Rather than introducing an obviously malicious driver, attackers bring a legitimate, signed driver containing a known security weakness and abuse that vulnerability to interact with the Windows kernel.
BYOVD has become an increasingly useful technique for attackers because security products are naturally more willing to trust properly signed drivers from recognised hardware vendors.
In Lunex's case, the vulnerable AMD driver is used to interfere with security-related processes before the information stealer is deployed.
Security Software Keeps Running — but Becomes Blind
One of the more interesting elements of the attack is that Lunex reportedly does not simply terminate endpoint security processes.
Instead, the malware uses what researchers describe as kernel callback zeroing, interfering with the mechanisms security products use to monitor system activity. The security software may therefore continue appearing to operate normally while losing visibility into what is actually happening.
This is potentially more difficult to recognise than straightforward process termination. If an endpoint security tool suddenly stops running, monitoring systems can raise an obvious alert. A product that remains active but can no longer observe malicious behaviour creates a much quieter failure.
Ontinue describes this as a more subtle approach to EDR neutralisation: the defence remains running, but effectively becomes blind.
Existing Windows Protections Did Not Block the Driver
Researchers also found that common Windows driver protections did not prevent the specific PDFWKRNL.sys version used by Lunex from loading.
Testing reportedly showed that neither Hypervisor-Protected Code Integrity, or HVCI, nor the current Microsoft Vulnerable Driver Blocklist stopped this particular driver variant.
That is notable because the driver's hash had already been catalogued by the LOLDrivers project months earlier. The finding highlights an ongoing difficulty with BYOVD attacks: vulnerable signed drivers can sometimes remain usable even after the security community has documented their risks.
The gap gives attackers a legitimate pathway into kernel-level operations without needing to develop their own unsigned driver.
Seven Chromium Browsers Are Targeted
Once the security environment has been weakened, LunexStealer begins collecting information.
Researchers say the malware targets credentials and browser data from seven Chromium-based browsers:
The stolen data can include usernames, passwords, session cookies, and other browser information capable of giving attackers access to online accounts.
Session cookies are particularly valuable because they may allow attackers to reuse an already authenticated browser session without needing to know the victim's password.
Cryptocurrency Wallets Are Another Major Target
Lunex also searches compromised systems for cryptocurrency wallets.
The malware has been observed targeting desktop wallets including Bitcoin Core, Litecoin, Exodus, Atomic Wallet, and Electrum. Browser-based cryptocurrency extensions are targeted as well, including MetaMask, MetaMask Legacy, OKX Wallet, and SafePal Wallet.
If attackers obtain wallet files, credentials, or recovery information, the financial consequences can be immediate. Unlike fraudulent banking transactions, cryptocurrency transfers are generally difficult or impossible to reverse after the funds have been moved.
That makes cryptocurrency data a particularly attractive target for information-stealing malware.
Persistence Survives Reboots and Malware Removal
Lunex does not simply steal information and disappear. Researchers identified several mechanisms designed to maintain access after the initial infection.
These include a Registry Run key, a hidden scheduled task called psychedelicloveUtils, and a Chrome Native Messaging Host.
The Native Messaging Host is particularly interesting because it allows the malware to continue interacting with the system through Chrome even if the original stealer executable is removed.
Researchers found that the component is backed by an embedded PowerShell script measuring roughly 13KB. It implements Chrome's Native Messaging protocol through standard input and output and runs within the browser's context.
According to Ontinue, the mechanism can survive system reboots, browser restarts, and deletion of the original stealer binary.
The PowerShell Component Provides Remote File Access
The persistence mechanism also gives attackers surprisingly broad control over the victim's filesystem.
Researchers identified six supported actions:
list_drives — enumerate available drive letters from C through Zlist_dir — list files and directoriesread_file — retrieve files in chunkswrite — write arbitrary data to selected file pathsdownload — download files from the compromised machinerun — execute arbitrary programsThis transforms Lunex from a straightforward credential stealer into something much closer to a persistent remote-access capability.
An attacker who maintains access through the Native Messaging Host could continue browsing files, retrieving documents, writing new content, or executing programs long after the original infection occurred.
A Malicious Chrome Extension Gives Even More Control
LunexStealer also manipulates Chrome's Secure Preferences to inject a malicious browser extension.
The extension requests extensive permissions covering cookies, browsing history, bookmarks, tabs, storage, proxy configuration, scripting, network request modification, and access to HTTP and HTTPS websites.
With those permissions, attackers gain extremely broad visibility into the victim's browser activity.
That can expose far more than passwords. Browser sessions often contain access to corporate systems, cloud platforms, personal accounts, webmail, collaboration tools, and financial services.
The extension therefore becomes another persistence and surveillance layer sitting directly inside the user's normal browsing environment.
Lunex Infrastructure Is Expanding Rapidly
The earliest public references to Lunex appeared in June 2026, when researchers identified six active command-and-control panels.
More recent analysis found 28 unique Lunex panels distributed across 13 countries, showing substantial growth in only a few months.
Infrastructure has been observed in locations including Russia, the United States, the United Kingdom, the Netherlands, France, Germany, Turkey, Bangladesh, and Ukraine.
That expansion supports the theory that Lunex is being operated as a broader criminal platform rather than a one-off malware campaign.
The Platform Also Supports Phishing Operations
One Lunex panel hosted in Turkey was linked to several phishing domains impersonating recognisable organisations and brands.
These included domains designed to resemble Sam's Club, Teamwork, Namshi, WhatsApp Business, and Ibraq Perfumes.
This suggests the Lunex platform goes beyond credential-stealing malware and provides infrastructure capable of supporting brand impersonation and phishing campaigns as well.
That makes the ecosystem more versatile for criminals because the same platform can potentially handle victim acquisition, malware deployment, credential collection, persistence, and follow-up fraud.
Why the BYOVD Technique Is Particularly Concerning
Using vulnerable drivers is not new, but employing BYOVD immediately before deploying an information stealer is less common.
Information stealers traditionally rely heavily on user-space techniques and attempt to move quickly before security tools detect them. Lunex instead invests more effort in weakening those protections before collecting information.
That can make the malware more reliable once it reaches the victim.
The use of a signed AMD driver also demonstrates why defenders cannot simply divide software into "trusted vendor" and "malicious application." Legitimate components containing exploitable vulnerabilities can become extremely powerful offensive tools when placed in the wrong context.
ClickFix Remains an Effective Social Engineering Technique
The campaign also shows why ClickFix-style attacks continue appearing across malware operations.
Fake verification pages are effective because users already expect websites to display CAPTCHA checks, browser verification screens, and Cloudflare protection pages. Attackers exploit that familiarity by presenting instructions that appear to be part of an ordinary security check.
Once the user follows those instructions, the infection chain can bypass some of the controls that would normally block an automatic download.
The user effectively becomes part of the execution process.
That makes awareness particularly important. Unexpected instructions asking users to run commands, install MSI packages, paste PowerShell content, or perform unusual verification steps should always be treated with suspicion.
Final Thoughts
Lunex illustrates how modern information stealers are evolving into much broader attack platforms.
The campaign begins with compromised websites and fake verification prompts, escalates privileges through Windows techniques, abuses a vulnerable AMD driver to reduce security visibility, and then deploys a credential stealer capable of targeting browsers and cryptocurrency wallets.
But the operation does not stop after the initial theft.
Registry persistence, scheduled tasks, a malicious Chrome extension, and a PowerShell-based Native Messaging Host give attackers continued access to the compromised machine and its filesystem. Meanwhile, the growing collection of command-and-control panels suggests that Lunex is expanding as a commercial malware-as-a-service ecosystem rather than remaining with a single operator.
Perhaps the most concerning aspect is how many legitimate technologies are involved in the attack chain: a real AMD driver, normal Windows mechanisms, Chrome Native Messaging, PowerShell, and familiar Cloudflare-style verification pages.
The individual tools may look trustworthy.
It is the way they are combined that makes Lunex dangerous.


Comments 0