Posted in

Lunex Malware Uses Psychedelic Stealer to Target Ukrainian Users

A malware-as-a-service (MaaS) platform known as Lunex is behind the distribution of the Psychedelic Stealer, an information-stealing malware campaign targeting Ukrainian-speaking users through compromised websites and fake Cloudflare verification pages.

According to cybersecurity company Ontinue, the campaign uses a four-stage infection chain that begins with a fake CAPTCHA and ends with the deployment of a fully featured command-and-control (C2) agent.

The malware can steal credentials from multiple Chromium-based browsers, extract cryptocurrency wallet information and establish persistent remote access to the victim’s filesystem.

“The attack chain begins with a fake CAPTCHA page and culminates in the deployment of a fully-featured C2 agent,” Ontinue threat researcher Rhys Downing said in a technical report.

The campaign uses ClickFix-style social engineering, where victims are instructed to perform actions on their computers under the guise of completing a security verification.

Fake CAPTCHA Leads to Lunex Malware

The attack begins when users visit compromised Ukrainian websites that have been modified to display a fraudulent Cloudflare-style verification page.

Earlier research by Arctic Wolf Labs found that legitimate websites belonging to organizations including a hair-treatment clinic, a scale-model manufacturer, a specialist bookseller, a psychological facility, a tool retailer and an automotive retailer had been compromised and modified to display the ClickFix lure.

The fake verification process ultimately delivers a malicious MSI installer, which triggers the next stages of the infection.

The installer deploys a loader known as LunexLoader. The loader is designed to bypass Windows User Account Control (UAC), evade security software and ultimately download the Psychedelic Stealer payload.

Lunex Uses a Vulnerable Driver to Disable Security Tools

One of the most notable elements of the attack is its use of a Bring Your Own Vulnerable Driver (BYOVD) technique.

Under this approach, attackers abuse a legitimate but vulnerable kernel-mode driver to gain elevated privileges or interfere with security software.

Lunex exploits a vulnerable driver associated with AMD Radeon Software, identified as PDFWKRNL.sys. The driver is affected by CVE-2023-20598.

According to Ontinue, the malware uses the vulnerable driver to interfere with security-related processes while allowing those processes to remain active.

This differs from more obvious attacks that simply terminate security software. Instead, the technique can leave security products running while preventing them from seeing malicious activity.

“The BYOVD delivery chain, using PDB-guided kernel callback zeroing rather than process termination, represents a quieter approach to EDR neutralisation that leaves security products running but blind,” Ontinue said.

Researchers said testing showed that neither Hypervisor-Protected Code Integrity (HVCI) nor Microsoft’s current Vulnerable Driver Blocklist prevented the specific PDFWKRNL.sys variant used in the attack from loading.

The driver hash had also been catalogued in the LOLDrivers project since March 2026.

Psychedelic Stealer and LunexStealer Are the Same Malware

Psychedelic Stealer was documented earlier by Arctic Wolf Labs, while earlier research had identified malware called LunexStealer.

Despite the different names, researchers say the two refer to the same malware component.

Ontinue explained that Psychedelic is the name of the malware file deployed to victims, while Lunex refers to the broader MaaS platform being sold or provided to multiple criminal groups.

This distinction is important because Lunex is more than a single malware sample. It includes the infrastructure used to build, distribute and control the malware.

LunexStealer Targets Browser Credentials and Crypto Wallets

Once executed, LunexStealer communicates with its C2 infrastructure over HTTP.

Researchers observed communication with the address:

193.178.159[.]128

The malware is capable of collecting credentials from at least seven Chromium-based browsers:

  • Google Chrome
  • Microsoft Edge
  • Brave
  • Yandex Browser
  • Opera
  • Opera GX
  • Vivaldi

The malware also searches for cryptocurrency wallet data.

It can target several desktop wallets, including:

  • Bitcoin Core
  • Litecoin
  • Exodus
  • Atomic Wallet
  • Electrum

It also targets browser-based wallet extensions, including:

  • MetaMask
  • MetaMask Legacy
  • OKX Wallet
  • SafePal Wallet

This combination gives attackers access to both stored browser credentials and potentially valuable cryptocurrency-related information.

Multiple Persistence Mechanisms

LunexStealer uses several techniques to maintain access to compromised Windows systems.

Researchers identified persistence through:

  • A Windows Registry Run key
  • A hidden scheduled task named psychedelicloveUtils
  • A Chrome Native Messaging Host (NMH)

The Native Messaging Host is particularly significant because it allows the malware to establish deeper interaction between Chrome and the attacker’s code.

According to Ontinue, the host contains a 13,200-byte PowerShell script embedded in the malware’s .rdata section.

The script implements the Chrome Native Messaging protocol using standard input and output.

Researchers said the component can survive:

  • Deletion of the original stealer executable
  • System reboots
  • Browser restarts

Persistent Remote File Access

The PowerShell-based Native Messaging Host provides attackers with several filesystem capabilities.

The commands identified by researchers include:

  • list_drives — Enumerates drive letters from C through Z.
  • list_dir — Lists directory contents and file sizes.
  • read_file — Reads files in 512 KB chunks, including files up to 524 MB.
  • write — Writes attacker-controlled data to arbitrary file paths.
  • download — Downloads files from the compromised system.
  • run — Executes programs on the victim’s machine.

This means Lunex is not limited to stealing browser passwords or cryptocurrency information. Its infrastructure can also provide attackers with ongoing remote access to the victim’s filesystem.

Malicious Chrome Extension Adds More Visibility

LunexStealer can also manipulate Chrome’s Secure Preferences to inject a malicious browser extension.

The extension requests extensive permissions covering:

  • Cookies
  • Browsing history
  • Bookmarks
  • Tabs
  • Storage
  • Proxy settings
  • Scripting
  • Network request controls
  • HTTP and HTTPS websites

Those permissions can give the attacker extensive visibility into the victim’s browser activity.

Combined with the credential-stealing capabilities already built into the malware, the extension provides another mechanism for monitoring and collecting information from compromised users.

Lunex Infrastructure Is Expanding

The earliest known references to Lunex date back to June 2026, when researcher Luke Wilkinson of BlueTeamCoolTeam identified six active Lunex Stealer C2 panels.

Those panels were located across the United States, Finland, Germany, the Netherlands and Ukraine.

Ontinue’s more recent analysis identified 28 unique panels across 13 countries, indicating substantial growth in the platform’s infrastructure.

The panels were hosted in countries including:

  • Russia
  • United States
  • United Kingdom
  • Netherlands
  • France
  • Germany
  • Turkey
  • Bangladesh

“That growth in just a few months shows the platform is actively expanding and being used by either one threat actor or sold for other actors, not just a single operator,” Downing said.

The infrastructure expansion supports the assessment that Lunex is operating as a MaaS platform rather than as a tool used exclusively by a single criminal group.

Lunex Infrastructure Also Supports Phishing

Researchers found evidence that the platform’s capabilities extend beyond information theft.

One Lunex panel hosted in Turkey was associated with several domains that appear designed to impersonate legitimate brands and services:

  • account-sams-club[.]com
  • teamwork-recover-password[.]com
  • namshi-uae[.]com
  • whatsappbusineses[.]com
  • ibraq-perfumes[.]com

The infrastructure suggests that Lunex customers may have access to tools for both malware distribution and phishing operations.

This broadens the platform’s potential use beyond stealing browser credentials and cryptocurrency data.

ClickFix Remains a Key Delivery Method

The campaign also demonstrates how ClickFix-style attacks are being combined with increasingly sophisticated malware.

Instead of exploiting a software vulnerability directly, ClickFix attacks manipulate users into executing commands or installing software themselves.

The fake CAPTCHA or Cloudflare verification page creates the appearance of a legitimate security check. The victim is then guided through actions that ultimately initiate the malware installation.

In the Lunex campaign, that technique serves as the entry point for the multi-stage infection chain.

Security Implications

The Lunex campaign combines several techniques that can make detection and response more difficult: compromised legitimate websites, social engineering, malicious installers, UAC bypass, vulnerable-driver exploitation, browser credential theft, cryptocurrency theft and persistent remote access.

The use of BYOVD is particularly notable because it attempts to undermine endpoint security without necessarily terminating security processes.

The combination of a MaaS business model and expanding C2 infrastructure also suggests that the technology can be operated by multiple criminal customers rather than a single threat actor.

For defenders, the campaign highlights the importance of monitoring suspicious MSI installations, unexpected driver loading, unusual PowerShell activity, unauthorized Chrome Native Messaging Hosts and modifications to browser security preferences.

Organizations should also treat unexpected CAPTCHA or Cloudflare verification instructions that ask users to download software or execute commands as a potential warning sign.

Lunex Highlights the Evolution of Malware-as-a-Service

The Lunex platform illustrates how modern MaaS operations are combining information stealers with persistence, remote filesystem access, phishing infrastructure and defense-evasion techniques.

Psychedelic Stealer is capable of harvesting browser credentials and cryptocurrency wallet information, while the broader Lunex platform provides the infrastructure needed to maintain access and operate compromised systems.

With researchers identifying a growing number of C2 panels across multiple countries, Lunex appears to be expanding beyond an isolated malware campaign into a broader criminal service ecosystem.

Leave a Reply

Your email address will not be published. Required fields are marked *