
Lunex Stealer Uses a Vulnerable AMD Driver to Blind Defenses and Steal Browser Credentials
Ontinue researchers have detailed Lunex, a malware-as-a-service platform whose stealer abuses a vulnerable AMD Radeon driver to blind endpoint defenses, then harvests passwords, cookies and crypto wallets from seven Chromium browsers.
Psychedelic Stealer, malware spread through compromised Ukrainian websites with ClickFix-style fake Cloudflare checks, is part of a wider malware-as-a-service (MaaS) platform called Lunex, according to a technical report from the security firm Ontinue. Its four-stage attack chain targets Ukrainian-speaking users.
"The attack chain begins with a fake CAPTCHA page and culminates in the deployment of a fully-featured C2 agent," said Ontinue threat researcher Rhys Downing. The stealer pulls credentials from seven Chromium-based browsers and installs a PowerShell-based Native Messaging Host for persistent remote filesystem access.
From a fake CAPTCHA to a stealer
Infection starts with bogus MSI installers delivered via ClickFix. A loader called LunexLoader bypasses User Account Control (UAC) on Windows with the CMSTPLUA COM object, uses a bring your own vulnerable driver (BYOVD) step for defense evasion and then downloads the stealer payload.
A vulnerable AMD driver blinds defenses
BYOVD is rarely seen ahead of a final-stage payload such as an information stealer. Lunex exploits a vulnerable kernel-mode AMD Radeon Software driver, PDFWKRNL.sys, tied to CVE-2023-20598, to escalate privileges and blind security processes while leaving them running.
"Before the stealer is delivered, the malware is designed to use a legitimate but vulnerable driver to switch off security tools on the victim's machine," Downing told The Hacker News. Ontinue says the chain zeroes kernel callbacks with PDB guidance instead of killing processes, leaving defenses running but blind; neither HVCI nor Microsoft's Vulnerable Driver Blocklist blocked this PDFWKRNL.sys variant.
What is stolen and how it persists
LunexStealer talks to a Lunex panel at 193.178.159[.]128 over HTTP, sweeps five desktop crypto wallets plus the MetaMask, OKX and SafePal extension wallets, and covers seven browsers, among them Google Chrome, Microsoft Edge and Brave. Persistence rests on a Registry Run key, a hidden scheduled task named "psychedelicloveUtils" and a Chrome native messaging host backed by a 13,200-byte PowerShell script that survives reboots and browser restarts.
28 panels in 13 countries
BlueTeamCoolTeam's Luke Wilkinson found six active Lunex panels in June 2026 across five countries. Ontinue now counts 28 unique panels in 13 countries and points to a Russian-speaking developer; one Turkish-hosted panel drives five phishing domains, adding brand impersonation to credential theft.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.