Lunex Malware-as-a-Service Platform Expands Reach with Sophisticated BYOVD Attacks
A sophisticated malware-as-a-service (MaaS) platform known as **Lunex** is rapidly expanding its operations, utilizing a unique blend of initial access methods and advanced defense evasion techniques. This platform, which distributes the **Psychedelic Stealer**, leverages compromised Ukrainian websites and a rare 'bring your own vulnerable driver' (BYOVD) attack to disable security tools before exfiltrating sensitive user data.
The **Psychedelic Stealer** malware, initially observed being distributed via compromised Ukrainian websites using **ClickFix**-style **Cloudflare** verification checks, has been identified as part of a broader MaaS platform named **Lunex**. New findings from **Ontinue** detail a four-stage attack chain primarily targeting Ukrainian-speaking users.
### The Attack Chain Unveiled
**Ontinue** threat researcher **Rhys Downing** described the intricate process: "The attack chain begins with a fake CAPTCHA page and culminates in the deployment of a fully-featured C2 agent." The stealer is designed to extract credentials and data from seven **Chromium**-based browsers, exfiltrate cryptocurrency wallets, and establish persistent remote filesystem access through a **PowerShell**-based Native Messaging Host within the victim's browser.
### Bypassing Defenses with BYOVD
Infection begins with bogus **MSI** installers delivered via **ClickFix**, which deploy a loader dubbed **LunexLoader**. This loader is engineered to bypass User Account Control (**UAC**) on **Windows** using the **CMSTPLUA COM** object. Crucially, it then employs a BYOVD attack for defense evasion, a technique rarely seen as a precursor to an information stealer.
**Lunex** exploits a vulnerability (**CVE-2023-20598**) in a kernel-mode driver for **AMD Radeon Software** (**"PDFWKRNL.sys"**). This allows it to escalate privileges and effectively blind security-related processes while keeping them running, thus avoiding detection.

### Initial Distribution and Modus Operandi
**Arctic Wolf Labs** first documented **Psychedelic Stealer** earlier this week, detailing how threat actors compromise legitimate websites β including those of a hair-treatment clinic, a scale-model manufacturer, and a psychological facility β to inject an iframe serving the **ClickFix** lure.
"Our analysis of the attack chain found that, before the stealer is delivered, the malware is designed to use a legitimate but vulnerable driver to switch off security tools on the victim's machine. With those protections disabled, the information stealer is then deployed to take browser passwords, session cookies, and cryptocurrency wallet data," **Downing** explained.
### The Lunex Platform: A Growing Threat
References to **Lunex** in cybersecurity literature date back to June 2026, when **BlueTeamCoolTeam's Luke Wilkinson** identified six active **Lunex Stealer** command-and-control (**C2**) panels across the U.S., Finland, Germany, the Netherlands, and Ukraine.
It's important to note that **Psychedelic Stealer** and **LunexStealer** refer to the same component of the **MaaS** platform. "'Psychedelic' is the name of the malware file that runs on victims' devices, while **Lunex** is the underlying platform being sold to multiple criminal groups," **Downing** clarified.

Upon execution, **LunexStealer** communicates with the **Lunex** panel at `193.178.159[.]128` over **HTTP** to facilitate comprehensive information theft:
* Stealing credentials from **Google Chrome**, **Microsoft Edge**, **Brave**, **Yandex Browser**, **Opera**, **Opera GX**, and **Vivaldi**.
* Enumerating and exfiltrating data from five desktop cryptocurrency wallets (**Bitcoin Core**, **Litecoin**, **Exodus**, **Atomic Wallet**, and **Electrum**) and four browser extension wallets (**MetaMask**, **MetaMask Legacy**, **OKX Wallet**, and **SafePal Wallet**).
* Establishing persistence via a Registry Run key, a hidden scheduled task named **"psychedelicloveUtils,"** and registering a **Chrome** native-messaging bridge or host (**NMH**) that allows for additional actions.
### Persistent Access and Browser Control
**Downing** further detailed the **NMH**: "The host is backed by a 13,200-byte **PowerShell** script embedded in the `.rdata` section that implements the **Chrome** Native Messaging protocol over standard input and output." This **NMH** operates within **Chrome's** process context, surviving binary deletion, system reboots, and browser restarts.
The **PowerShell** script supports six file system actions:
* `list_drives`: To enumerate all drive letters C through Z.
* `list_dir`: To list directory contents with file sizes.
* `read_file`: To read arbitrary files in 512 KB chunks, up to 524 MB.
* `write`: To write arbitrary data to any file path.
* `download`: To download files from the system.
* `run`: To execute arbitrary programs.
Additionally, **LunexStealer** injects a malicious **Chrome** extension by manipulating **Chrome Secure Preferences**, requesting extensive permissions over cookies, history, bookmarks, tabs, storage, proxy, scripting, **declarativeNetRequest**, and all **HTTP** and **HTTPS** URLs. This grants the extension complete visibility and control over a victim's browser activity.
### Global Reach and Phishing Capabilities
Analysis of the **Lunex** panel indicates a Russian-speaking developer or team, with 28 unique panels now identified across 13 countries, a significant expansion since June 2026. These panels are hosted in Russia, the U.S., the U.K., the Netherlands, France, Germany, Turkey, and Bangladesh.
"That growth in just a few months shows the platform is actively expanding and being used by either one threat actor or sold for other actors, not just a single operator," **Downing** noted.
One panel hosted in Turkey has been linked to five phishing domains: `account-sams-club[.]com`, `teamwork-recover-password[.]com`, `namshi-uae[.]com`, `whatsappbusineses[.]com`, and `ibraq-perfumes[.]com`. This suggests the **MaaS** platform's capabilities extend beyond credential theft to include brand impersonation and phishing.
### EDR Evasion and Persistent Gaps
**Ontinue** highlighted the sophistication of the evasion techniques: "The **BYOVD** delivery chain, using **PDB**-guided kernel callback zeroing rather than process termination, represents a quieter approach to **EDR** neutralization that leaves security products running but blind."
Validated testing has shown that neither **HVCI** nor the current **Microsoft Vulnerable Driver Blocklist** prevents the specific **PDFWKRNL.sys** variant used by **Lunex** from loading. This gap persists despite the driver hash being cataloged in the **LOLDrivers** project since March 2026.

LunexStealer (aka Psychedelic Stealer) C2 Panel | Source: BlueTeamCoolTeam