Psychedelic Stealer Linked to Lunex Malware-as-a-Service Platform
The Psychedelic Stealer malware recently distributed through compromised Ukrainian websites using ClickFix-style fake Cloudflare verification pages is part of a broader malware-as-a-service (MaaS) platform called Lunex.
Security researchers identified a four-stage infection chain targeting Ukrainian-speaking users. The campaign begins with a fake CAPTCHA page and eventually deploys a fully featured command-and-control agent capable of stealing credentials, cryptocurrency wallet data, and providing persistent remote access.
Four-Stage Attack Chain
The infection begins with a fake CAPTCHA or Cloudflare verification page hosted on compromised legitimate websites.
The ClickFix lure instructs victims to copy and execute a malicious command through the Windows Run dialog.
The attack then uses fake MSI installers to deliver LunexLoader, which performs several security-bypass and privilege-escalation operations before deploying Psychedelic Stealer.
The main stages include:
- Fake Cloudflare verification and ClickFix lure
- Malicious MSI installer and LunexLoader
- BYOVD-based security evasion
- Psychedelic Stealer deployment
LunexLoader Uses a Vulnerable AMD Driver
LunexLoader uses the Bring Your Own Vulnerable Driver (BYOVD) technique to bypass security protections.
The malware abuses PDFWKRNL.sys, a vulnerable kernel-mode driver associated with AMD Radeon Software.
The driver is affected by CVE-2023-20598, which can be exploited to obtain elevated privileges.
Instead of simply terminating security software, the malware uses kernel-level techniques to interfere with security-related processes while allowing them to remain running.
This approach can make endpoint security tools appear operational while limiting their ability to detect malicious activity.
Researchers reported that testing showed the specific driver variant used in the campaign could load despite HVCI and the current Microsoft Vulnerable Driver Blocklist.
Psychedelic Stealer Capabilities
Psychedelic Stealer communicates with the Lunex infrastructure over HTTP and can collect a wide range of sensitive information.
It targets credentials from:
- Google Chrome
- Microsoft Edge
- Brave
- Yandex Browser
- Opera
- Opera GX
- Vivaldi
The malware also searches for cryptocurrency data from desktop wallets including:
- Bitcoin Core
- Litecoin Core
- Exodus
- Atomic Wallet
- Electrum
Browser-based wallets targeted include:
- MetaMask
- MetaMask Legacy
- OKX Wallet
- SafePal Wallet
Multiple Persistence Mechanisms
LunexStealer establishes persistence through several mechanisms, including:
- Registry Run keys
- A hidden scheduled task named
psychedelicloveUtils - A Chrome Native Messaging Host
The Native Messaging Host provides the malware with additional control over the browser environment.
The host contains a PowerShell script that implements the Chrome Native Messaging protocol through standard input and output.
Researchers found that this component can survive deletion of the main stealer, system reboots, and browser restarts.
Persistent Remote File Access
The PowerShell-based Native Messaging Host supports multiple filesystem operations:
list_drivesto enumerate drive letterslist_dirto list directory contents and file sizesread_fileto read fileswriteto modify filesdownloadto retrieve filesrunto execute programs
This effectively gives operators persistent remote access to the victim's filesystem beyond the initial credential-stealing functionality.
Malicious Chrome Extension
LunexStealer can also inject a malicious Chrome extension by modifying Chrome's Secure Preferences.
The extension requests extensive permissions covering:
- Cookies
- History
- Bookmarks
- Tabs
- Storage
- Proxy settings
- Scripting
- Network request controls
- HTTP and HTTPS websites
These permissions can provide extensive visibility into and control over browser activity.
Lunex Malware-as-a-Service Platform
Researchers found evidence that Psychedelic Stealer and LunexStealer refer to the same malware component.
Psychedelic is the name used for the malware file deployed on victims, while Lunex refers to the broader platform that is reportedly offered to multiple criminal operators.
The earliest known references to Lunex date back to June 2026, when researchers identified six active C2 panels across several countries.
More recent analysis identified 28 unique panels across 13 countries, indicating significant expansion of the platform.
The panels were identified in locations including:
- Russia
- United States
- United Kingdom
- Netherlands
- France
- Germany
- Turkey
- Bangladesh
Analysis of the infrastructure suggests a Russian-speaking developer or development team, although the available evidence does not establish a specific threat actor.
Phishing Capabilities
The Lunex infrastructure is not limited to information theft.
One panel hosted in Turkey was found resolving to several phishing domains, including:
account-sams-club[.]com teamwork-recover-password[.]com namshi-uae[.]com whatsappbusineses[.]com ibraq-perfumes[.]com
This suggests that the platform can also support brand impersonation and phishing operations.
Why the BYOVD Technique Matters
The use of BYOVD is particularly notable because the technique is being used as a precursor to an information-stealing payload.
The campaign uses a vulnerable kernel driver to interfere with security protections without necessarily terminating security software.
Researchers described this as a quieter approach to security-tool evasion because affected security processes can remain active while their ability to monitor malicious activity is reduced.
The specific driver hash had reportedly been documented in the LOLDrivers project since March 2026, yet the protections tested by researchers did not prevent the driver from loading.
Key Takeaway
The Lunex platform demonstrates how modern malware-as-a-service operations can combine ClickFix social engineering, UAC bypasses, BYOVD-based security evasion, credential theft, cryptocurrency theft, browser manipulation, and persistent remote access into a single attack chain.
The connection between Psychedelic Stealer and Lunex also shows how a malware component initially observed in a targeted campaign can be part of a broader platform designed for use by multiple criminal operators.