Lunex Stealer Exploits AMD Driver Vulnerability to Evade Security and Harvest Browser Credentials

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

The Psychedelic Stealer malware, distributed via compromised Ukrainian websites, is part of a broader malware-as-a-service (MaaS) platform known as Lunex. Recent findings from Ontinue reveal a sophisticated four-stage attack chain targeting Ukrainian-speaking users.

According to Ontinue threat researcher Rhys Downing, the attack begins with a fake CAPTCHA page and culminates in the deployment of a fully-featured command-and-control (C2) agent. The stealer is capable of extracting credentials and data from seven Chromium-based browsers, exfiltrating cryptocurrency wallets, and establishing persistent remote filesystem access through a PowerShell-based Native Messaging Host installed within the victim’s browser.

Exploitation of AMD Driver Vulnerability

The infection process utilizes bogus MSI installers delivered via ClickFix to execute a series of actions, including the delivery of a loader named LunexLoader. This loader is designed to bypass User Account Control (UAC) on Windows by leveraging the bring your own vulnerable driver (BYOVD) technique, specifically exploiting a vulnerable kernel-mode driver for AMD Radeon Software (“PDFWKRNL.sys”), which is susceptible to CVE-2023-20598.

This exploitation allows the malware to escalate privileges and blind security-related processes while keeping them operational. The use of BYOVD is particularly notable as it is rarely employed as a precursor to a final-stage payload like an information stealer.

Operational Insights and Expansion

Psychedelic Stealer was first documented earlier this week by Arctic Wolf Labs, which detailed the threat actor’s method of compromising legitimate websites to inject an iframe element designed to serve the ClickFix lure. The earliest reference to Lunex in cybersecurity literature dates back to June 2026, when BlueTeamCoolTeam identified six active Lunex Stealer command-and-control panels across the U.S., Finland, Germany, the Netherlands, and Ukraine.

Upon execution, LunexStealer communicates with the Lunex panel at 193.178.159[.]128 over HTTP to facilitate comprehensive information theft, including stealing credentials from various browsers and enumerating multiple cryptocurrency wallets. The malware establishes persistence through a Registry Run key and a hidden scheduled task, ensuring its continued operation even after system reboots.

Analysis of the Lunex panel indicates a Russian-speaking developer or team, with 28 unique panels identified across 13 countries, marking significant expansion from June 2026. This growth suggests that the platform is actively being used by multiple threat actors, not just a single operator.

One of the panels hosted in Turkey has been linked to several phishing domains, indicating that the MaaS platform’s capabilities extend beyond credential theft to include brand impersonation and phishing activities.

Ontinue noted that the BYOVD delivery chain represents a quieter approach to evading endpoint detection and response (EDR) systems, leaving security products running but ineffective. Validated testing has shown that neither HVCI nor the current Microsoft Vulnerable Driver Blocklist prevents the specific PDFWKRNL.sys variant used in this chain from loading, highlighting a significant gap in current security measures.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

CIDAR challenge advances passive imaging algorithms for ranging

The recently concluded Computational Imaging Detection and Ranging (CIDAR) challenge, organized by DARPA, aimed to advance passive imaging algorithms for measuring distances up to...

F5 Issues Advisory for CVE-2026-94127, Critical RCE Vulnerability in BIG-IP APM

Critical RCE Vulnerability in F5 BIG-IP APM: CVE-2026-94127 On September 22, 2026, F5 Networks issued a security advisory regarding CVE-2026-94127, a critical heap-based buffer overflow...

Former Army Soldier Sentenced to 70 Months for Cyber Attacks on AT&T and Snowflake

A former Army soldier, Cameron John Wagenius, has been sentenced to 70 months in prison for a series of cyber attacks and extortion attempts...

Unit 42 Experts Address Common Cybersecurity Myths and Misconceptions

In the ever-evolving landscape of cybersecurity, misconceptions can lead organizations to adopt ineffective strategies that leave them vulnerable to attacks. Insights from Unit 42...