A sophisticated and expanding malware-as-a-service (MaaS) platform known as Lunex is driving a wave of targeted cyberattacks against Ukrainian-speaking users, leveraging compromised websites, deceptive verification checks, and advanced kernel-level evasion techniques.

Recent findings from cybersecurity researchers at Ontinue have shed light on the mechanics of the platform, revealing a structured four-stage attack chain that culminates in the deployment of a fully featured command-and-control agent. This threat actor infrastructure distributes a component known as Psychedelic Stealer—alternatively tracked as LunexStealer—which is designed to plunder sensitive user data, compromise cryptocurrency wallets, and establish persistent remote access to victim environments.

The campaign initially came to light when researchers observed threat actors compromising legitimate websites across Ukraine. The affected domains belonged to a diverse array of businesses and organizations, including a hair-treatment clinic, a scale-model manufacturer, a specialist bookseller, a psychological facility, a tool retailer, and an automotive retailer. Attackers injected malicious iframe elements into these trusted sites to serve fake Cloudflare verification pages using ClickFix-style social engineering lures.

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

Anatomy of the Lunex Attack Chain

According to technical analysis published by Ontinue threat researcher Rhys Downing, the infection vector begins when unsuspecting visitors interact with the bogus CAPTCHA and verification pages. This interaction prompts the download of deceptive Microsoft Installer (MSI) packages that initiate a sequence of covert operations.

The payload delivery mechanism relies on a loader designated as LunexLoader. This loader is explicitly engineered to bypass Windows User Account Control (UAC) mechanisms by abusing the CMSTPLUA COM object. Following this initial privilege escalation phase, the malware executes defense evasion routines by employing the "bring your own vulnerable driver" (BYOVD) technique before finally downloading and executing the core information-stealer payload.

The use of the BYOVD technique represents a particularly notable escalation in sophistication for an information-stealing campaign. Rather than terminating security solutions outright, the Lunex platform utilizes a legitimate but vulnerable kernel-mode driver associated with AMD Radeon Software, specifically the "PDFWKRNL.sys" file. This driver is susceptible to a known security flaw tracked as CVE-2023-20598. By exploiting this vulnerability, the malware achieves kernel-level code execution, allowing it to systematically blind security-related processes and endpoint detection and response (EDR) tools while leaving them running in the background.

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

Ontinue researchers highlighted that neither Hypervisor-Protected Code Integrity (HVCI) nor current iterations of the Microsoft Vulnerable Driver Blocklist successfully prevent this specific variant of the PDFWKRNL.sys driver from loading. This persistence gap remains evident despite the driver hash having been catalogued within open-source vulnerability repositories since March 2026.

Capabilities of Psychedelic Stealer and LunexStealer

Once the targeted system’s protective mechanisms are neutralized, the Psychedelic Stealer payload establishes active communication with external infrastructure. Analysis indicates that the malware communicates with command-and-control panels hosted on the Lunex platform, such as an endpoint identified at 193.178.159[.]128 over HTTP, to facilitate comprehensive data exfiltration.

The stealer is programmed to harvest credentials, session cookies, and autofill data from at least seven different Chromium-based web browsers. In addition to browser data, the malware actively targets cryptocurrency wallet installations to siphon digital assets. Beyond mere data theft, the platform ensures long-term persistence by deploying a PowerShell-based Native Messaging Host directly into the victim’s browser environment.

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

This Native Messaging Host is backed by an embedded script within the binary’s data section that implements the Chrome Native Messaging protocol over standard input and output streams. Operating entirely within the context of the browser process, this persistence mechanism survives standard system reboots, browser restarts, and even the eventual deletion of the primary stealer binary. The underlying PowerShell script supports multiple file system and registry interactions, granting remote operators ongoing utility.

Furthermore, LunexStealer actively manipulates Chrome Secure Preferences to forcefully inject a malicious browser extension. This extension requests expansive permissions across cookies, browsing history, bookmarks, tabs, local storage, proxy configurations, scripting utilities, and network request manipulation interfaces. This grants the attackers profound visibility and administrative control over the victim’s day-to-day web browsing activities.

Global Expansion of the Lunex Infrastructure

The broader infrastructure supporting these attacks points toward a commercialized MaaS ecosystem operated by Russian-speaking developers. The earliest public identifications of the Lunex command-and-control panels emerged in June 2026, when researchers mapped active panels distributed across countries including the United States, Finland, Germany, the Netherlands, and Ukraine.

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

Subsequent tracking revealed a rapid geographical expansion of the platform. Investigators identified numerous unique panels distributed across multiple jurisdictions, including Russia, the United States, the United Kingdom, the Netherlands, France, Germany, Turkey, and Bangladesh. This rapid proliferation over a span of several months underscores that the Lunex platform is actively commercialized and utilized by multiple distinct threat actor groups rather than a single isolated operator.

Investigative findings also indicate that the operational scope of the Lunex ecosystem extends beyond standard credential harvesting. Infrastructure analysis linked certain panels—such as one hosted in Turkey—to several distinct phishing domains. This overlap suggests that the MaaS platform integrates capabilities tailored for brand impersonation and credential phishing campaigns alongside its core malware delivery features.

Cybersecurity analysts continue to monitor the evolution of the Lunex platform as organizations face increasingly complex threats that combine social engineering lures like ClickFix with low-level kernel exploits to subvert endpoint protections.

Leave a Reply

Your email address will not be published. Required fields are marked *