Skip to content

Security1 publisher2 min readPublished

Lunex sells a stealer that blinds security tools with a vulnerable AMD driver

Ontinue says the Lunex stealer-for-rent loads a flawed AMD driver, CVE-2023-20598, to switch off security tools before robbing seven browsers. That driver step is rarely used ahead of an info stealer, and Lunex is rented to multiple criminal groups.

The Watch · Security desk

What happened

  • Lunex spreads through hijacked Ukrainian websites that serve a ClickFix-style Cloudflare verification check, the lure that opens Ontinue's four-stage chain.
  • Ontinue calls Lunex a malware-as-a-service platform sold to multiple criminal groups, with 'Psychedelic' the name of the file that runs on each victim's machine.
  • A Chrome Native Messaging host backed by a 13,200-byte PowerShell script gives filesystem read, write and run and survives deleting the stealer binary, reboots and browser restarts.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • capability Because Lunex is rented, kernel-level defense evasion that once took skill now ships to any buyer of the platform.
  • constraint The driver blinds antivirus while leaving the process alive, so monitoring that only checks whether the agent is running will report a healthy endpoint.
  • exposure Cleanup that removes the stealer binary does not evict the attacker; the in-browser messaging host keeps remote file read, write and execute alive.

The driver is a signed AMD Radeon component, PDFWKRNL.sys, and CVE-2023-20598 lets Lunex escalate privileges and blind security processes while leaving them running [7]. Ontinue's Rhys Downing said: "Our analysis of the attack chain found that, before the stealer is delivered, the malware is designed to use a legitimate but vulnerable driver to switch off security tools on the victim's machine. With those protections disabled, the information stealer is then deployed to take browser passwords, session cookies, and cryptocurrency wallet data" [9]. Bring-your-own-vulnerable-driver is rarely used as a precursor to a final-stage payload like an information stealer [6].

Ontinue frames Psychedelic as one part of a rented platform, not a standalone tool [1]. Arctic Wolf Labs documented the malware earlier this week and detailed the operator's habit of compromising legitimate sites [8]. Downing drew the line between the two names: "'Psychedelic' is the name of the malware file that runs on victims' devices, while Lunex is the underlying platform being sold to multiple criminal groups, which is the reason for the name 'Lunex' and 'LunexStealer.'" [11] The earliest public reference to Lunex is from June 2026, when BlueTeamCoolTeam's Luke Wilkinson counted six active C2 panels across the U.S., Finland, Germany, the Netherlands, and Ukraine [10].

Arctic Wolf listed the compromised sites: a hair-treatment clinic, a scale-model manufacturer, a specialist bookseller, a psychological facility, a tool retailer, and an automotive retailer, each seeded with an iframe that serves the ClickFix lure [8]. From there a fake CAPTCHA leads to bogus MSI installers, which drop LunexLoader. The loader bypasses User Account Control through the CMSTPLUA COM object, runs the driver attack, and pulls down the stealer [5].

LunexStealer sets a Registry Run key, a hidden scheduled task named "psychedelicloveUtils," and a Chrome native-messaging host [15]. Downing said the host "is backed by a 13,200-byte PowerShell script embedded in the .rdata section that implements the Chrome Native Messaging protocol over standard input and output" [16]. It runs within Chrome's process context [18], and "survives stealer binary deletion, system reboots, and browser restarts" [17]. The script exposes six filesystem actions, including read_file in 512 KB chunks up to 524 MB, write to any path, download, and run to execute arbitrary programs [19].

Once running, LunexStealer talks to the Lunex panel at 193.178.159.128 over plain HTTP [12]. It pulls credentials from seven Chromium browsers [13] and enumerates nine cryptocurrency wallets, five desktop and four browser-extension [21][14]. It also drops a malicious Chrome extension by editing Chrome Secure Preferences, claiming access to cookies, history, bookmarks, tabs, and storage [20].

What to watch

  • Whether AMD's PDFWKRNL.sys lands on Microsoft's vulnerable-driver blocklist and breaks the BYOVD step.
  • Whether Lunex buyers expand targeting beyond Ukrainian-speaking users and the five countries seen hosting panels.
  • Whether more C2 panels surface beyond the six Wilkinson catalogued in June 2026.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories