Psychedelic Stealer Linked to Lunex Malware-as-a-Service Platform

The Psychedelic Stealer malware recently distributed through compromised Ukrainian websites using ClickFix-style fake Cloudflare verification pages is part of a broader malware-as-a-service (MaaS) platform called Lunex.

Security researchers identified a four-stage infection chain targeting Ukrainian-speaking users. The campaign begins with a fake CAPTCHA page and eventually deploys a fully featured command-and-control agent capable of stealing credentials, cryptocurrency wallet data, and providing persistent remote access.

Four-Stage Attack Chain

The infection begins with a fake CAPTCHA or Cloudflare verification page hosted on compromised legitimate websites.

The ClickFix lure instructs victims to copy and execute a malicious command through the Windows Run dialog.

The attack then uses fake MSI installers to deliver LunexLoader, which performs several security-bypass and privilege-escalation operations before deploying Psychedelic Stealer.

The main stages include:

  1. Fake Cloudflare verification and ClickFix lure
  2. Malicious MSI installer and LunexLoader
  3. BYOVD-based security evasion
  4. Psychedelic Stealer deployment

LunexLoader Uses a Vulnerable AMD Driver

LunexLoader uses the Bring Your Own Vulnerable Driver (BYOVD) technique to bypass security protections.

The malware abuses PDFWKRNL.sys, a vulnerable kernel-mode driver associated with AMD Radeon Software.

The driver is affected by CVE-2023-20598, which can be exploited to obtain elevated privileges.

Instead of simply terminating security software, the malware uses kernel-level techniques to interfere with security-related processes while allowing them to remain running.

This approach can make endpoint security tools appear operational while limiting their ability to detect malicious activity.

Researchers reported that testing showed the specific driver variant used in the campaign could load despite HVCI and the current Microsoft Vulnerable Driver Blocklist.

Psychedelic Stealer Capabilities

Psychedelic Stealer communicates with the Lunex infrastructure over HTTP and can collect a wide range of sensitive information.

It targets credentials from:

  • Google Chrome
  • Microsoft Edge
  • Brave
  • Yandex Browser
  • Opera
  • Opera GX
  • Vivaldi

The malware also searches for cryptocurrency data from desktop wallets including:

  • Bitcoin Core
  • Litecoin Core
  • Exodus
  • Atomic Wallet
  • Electrum

Browser-based wallets targeted include:

  • MetaMask
  • MetaMask Legacy
  • OKX Wallet
  • SafePal Wallet

Multiple Persistence Mechanisms

LunexStealer establishes persistence through several mechanisms, including:

  • Registry Run keys
  • A hidden scheduled task named psychedelicloveUtils
  • A Chrome Native Messaging Host

The Native Messaging Host provides the malware with additional control over the browser environment.

The host contains a PowerShell script that implements the Chrome Native Messaging protocol through standard input and output.

Researchers found that this component can survive deletion of the main stealer, system reboots, and browser restarts.

Persistent Remote File Access

The PowerShell-based Native Messaging Host supports multiple filesystem operations:

  • list_drives to enumerate drive letters
  • list_dir to list directory contents and file sizes
  • read_file to read files
  • write to modify files
  • download to retrieve files
  • run to execute programs

This effectively gives operators persistent remote access to the victim's filesystem beyond the initial credential-stealing functionality.

Malicious Chrome Extension

LunexStealer can also inject a malicious Chrome extension by modifying Chrome's Secure Preferences.

The extension requests extensive permissions covering:

  • Cookies
  • History
  • Bookmarks
  • Tabs
  • Storage
  • Proxy settings
  • Scripting
  • Network request controls
  • HTTP and HTTPS websites

These permissions can provide extensive visibility into and control over browser activity.

Lunex Malware-as-a-Service Platform

Researchers found evidence that Psychedelic Stealer and LunexStealer refer to the same malware component.

Psychedelic is the name used for the malware file deployed on victims, while Lunex refers to the broader platform that is reportedly offered to multiple criminal operators.

The earliest known references to Lunex date back to June 2026, when researchers identified six active C2 panels across several countries.

More recent analysis identified 28 unique panels across 13 countries, indicating significant expansion of the platform.

The panels were identified in locations including:

  • Russia
  • United States
  • United Kingdom
  • Netherlands
  • France
  • Germany
  • Turkey
  • Bangladesh

Analysis of the infrastructure suggests a Russian-speaking developer or development team, although the available evidence does not establish a specific threat actor.

Phishing Capabilities

The Lunex infrastructure is not limited to information theft.

One panel hosted in Turkey was found resolving to several phishing domains, including:

account-sams-club[.]com
teamwork-recover-password[.]com
namshi-uae[.]com
whatsappbusineses[.]com
ibraq-perfumes[.]com

This suggests that the platform can also support brand impersonation and phishing operations.

Why the BYOVD Technique Matters

The use of BYOVD is particularly notable because the technique is being used as a precursor to an information-stealing payload.

The campaign uses a vulnerable kernel driver to interfere with security protections without necessarily terminating security software.

Researchers described this as a quieter approach to security-tool evasion because affected security processes can remain active while their ability to monitor malicious activity is reduced.

The specific driver hash had reportedly been documented in the LOLDrivers project since March 2026, yet the protections tested by researchers did not prevent the driver from loading.

Key Takeaway

The Lunex platform demonstrates how modern malware-as-a-service operations can combine ClickFix social engineering, UAC bypasses, BYOVD-based security evasion, credential theft, cryptocurrency theft, browser manipulation, and persistent remote access into a single attack chain.

The connection between Psychedelic Stealer and Lunex also shows how a malware component initially observed in a targeted campaign can be part of a broader platform designed for use by multiple criminal operators.