A malware-as-a-service platform called Lunex is pushing a stealer that switches off endpoint defenses before it steals anything, leaning on a long-known flaw in an AMD graphics driver.
Ontinue tied the campaign to Psychedelic Stealer, the family Arctic Wolf described this week after it turned up on compromised Ukrainian websites behind fake Cloudflare checks. The names describe one operation: Psychedelic is the payload on a victim’s machine, while Lunex is the platform sold to criminal groups.
The chain runs in four stages. A bogus MSI, delivered through a ClickFix lure, drops LunexLoader. The loader bypasses Windows User Account Control through the CMSTPLUA COM object, then loads a vulnerable AMD Radeon Software kernel driver, PDFWKRNL.sys, tied to CVE-2023-20598. Using bring your own vulnerable driver, it escalates privileges and blinds security processes rather than terminating them.
From there the stealer drains credentials from seven Chromium browsers and pulls data from nine crypto wallets. It also installs a PowerShell native messaging host inside Chrome that survives reboots and deletion of the stealer binary, and that supports file reads, writes, downloads, and program execution.
Researchers found a malicious Chrome extension too, injected by editing Chrome Secure Preferences, holding permissions over cookies, history, bookmarks, tabs, proxy, and scripting.
The panel’s code points to a Russian-speaking developer, Ontinue said, with 28 panels now spread across 13 countries, up from six in June. One Turkish panel resolves to phishing domains impersonating retail and messaging brands.
Testing showed neither memory integrity protection nor Microsoft’s vulnerable driver blocklist stops this driver variant from loading.
