VYPR
researchPublished Sep 26, 2026· 1 source

Lunex Stealer Abuses AMD Driver to Evade Security and Steal Credentials

The Lunex malware-as-a-service platform is distributing Psychedelic Stealer, leveraging a vulnerable AMD driver to disable security monitoring and steal browser credentials from Ukrainian users.

A sophisticated malware-as-a-service (MaaS) operation known as Lunex is actively distributing a potent information stealer called Psychedelic Stealer. This campaign targets Ukrainian-speaking users through a multi-stage attack chain that begins with a deceptive CAPTCHA page, ultimately aiming to compromise sensitive user credentials and establish persistent access.

The infection vector involves bogus MSI installers delivered via a technique dubbed ClickFix, which triggers a series of actions. This includes the deployment of a loader named LunexLoader. This loader is designed to bypass User Account Control (UAC) on Windows systems using the CMSTPLUA COM object. Crucially, it then employs a bring-your-own vulnerable driver (BYOVD) attack for defense evasion, a technique rarely used as a precursor to final payload deployment.

The BYOVD technique is central to Lunex's evasion strategy. The malware exploits a vulnerable kernel-mode driver for AMD Radeon Software, specifically "PDFWKRNL.sys," which is susceptible to CVE-2023-20598. By leveraging this vulnerability, Lunex can escalate privileges and effectively blind security-related processes, including endpoint detection and response (EDR) solutions, while keeping them operational. This allows the stealer to operate undetected.

Psychedelic Stealer itself was recently documented by Arctic Wolf Labs, detailing how threat actors compromise legitimate Ukrainian websites. These compromised sites inject an iframe element that serves the ClickFix lure. Once the user interacts with the fake CAPTCHA, the attack chain proceeds, disabling security tools before deploying the information stealer to harvest browser passwords, session cookies, and cryptocurrency wallet data.

The Lunex MaaS platform, which also goes by the name LunexStealer, has seen significant expansion since its initial identification in June 2026. At that time, only six command-and-control (C2) panels were observed. However, analysis now points to a Russian-speaking developer or team behind the platform, with 28 unique panels identified across 13 countries, including Russia, the U.S., the U.K., and Germany. This rapid growth suggests active expansion and use by multiple threat actors.

Upon execution, LunexStealer communicates with its C2 panel to exfiltrate a wide range of data. This includes credentials from seven Chromium-based browsers (Google Chrome, Microsoft Edge, Brave, Yandex Browser, Opera, Opera GX, and Vivaldi), as well as sensitive information from cryptocurrency wallets. It also establishes persistence through Registry Run keys, hidden scheduled tasks, and by installing a native messaging host within the victim's browser, which allows for further actions even if the stealer binary is deleted or the system reboots.

Further complicating the threat, LunexStealer injects a malicious Chrome extension by manipulating Chrome's secure preferences. This extension declares extensive permissions, granting it complete visibility and control over a victim's browser activity, including cookies, history, bookmarks, and all HTTP/HTTPS URLs. The MaaS platform's capabilities also extend to brand impersonation and phishing, as evidenced by panels resolving to multiple phishing domains.

The use of a vulnerable AMD driver for defense evasion, specifically employing PDB-guided kernel callback zeroing rather than outright process termination, represents a quieter approach to EDR neutralization. This method leaves security products running but blind, a gap that neither HVCI nor Microsoft's Vulnerable Driver Blocklist currently prevents with this specific driver variant.

Synthesized by Vypr AI
Lunex Stealer Abuses AMD Driver to Evade Security and Steal Credentials · VYPR