The cybersecurity landscape is currently contending with a significant escalation in the distribution of the Psychedelic Stealer malware, a sophisticated information-stealing component now confirmed to be part of a rapidly proliferating Malware-as-a-Service (MaaS) ecosystem known as Lunex. Recent investigative findings from the security firm Ontinue have shed light on a multi-stage, highly evasive infection vector that specifically targets Ukrainian-speaking users, though the infrastructure supporting the campaign has now been identified across 13 countries. By combining deceptive "ClickFix" social engineering tactics with advanced kernel-level exploitation, the operators behind Lunex have established a persistent threat capable of bypassing modern endpoint detection and response (EDR) systems.
The Anatomy of the Lunex Infection Chain
The attack lifecycle begins with the compromise of legitimate websites, which are repurposed to serve as delivery vehicles for malicious payloads. Researchers have observed that a diverse array of businesses—ranging from Ukrainian hair-treatment clinics and specialist booksellers to automotive retailers and psychological facilities—have been compromised. These sites are injected with an iframe element that triggers a fake Cloudflare-style verification page, a tactic commonly referred to as "ClickFix."
When a user visits a compromised site, they are prompted to perform a "browser security check" or verification. This interaction is designed to deceive the user into manually executing a malicious Microsoft Installer (MSI) file. Once the user initiates this file, the four-stage infection chain commences:

- Loader Deployment: The MSI file executes LunexLoader, a primary component tasked with preparing the system for the full-featured payload.
- UAC Bypass and Privilege Escalation: The loader leverages the CMSTPLUA COM object to bypass User Account Control (UAC) prompts, granting the malware elevated privileges without alerting the user.
- Kernel-Mode Defense Evasion: Perhaps the most concerning aspect of this campaign is the integration of a "Bring Your Own Vulnerable Driver" (BYOVD) attack. The malware utilizes the vulnerable "PDFWKRNL.sys" driver—a component of AMD Radeon Software—to interact directly with the Windows kernel.
- Final Payload Delivery: With security solutions effectively blinded, the Psychedelic Stealer is deployed to exfiltrate browser credentials, session cookies, and cryptocurrency wallet data.
The Role of BYOVD in Modern Evasion
The use of the PDFWKRNL.sys driver is a strategic choice that highlights the evolving nature of malware development. By exploiting CVE-2023-20598, the attackers can perform kernel callback zeroing. Unlike traditional methods that attempt to kill security processes—which often trigger immediate alarms—this technique leaves antivirus and EDR software in a "running but blind" state.
Security researchers at Ontinue have noted that this approach is remarkably effective because the driver’s specific variant is not currently blocked by the Microsoft Vulnerable Driver Blocklist, despite being cataloged by the LOLDrivers project as early as March 2026. This gap in security enforcement allows the malware to maintain a presence on the host system while effectively neutralizing the very tools designed to detect it.
Chronology and Geographical Expansion
The emergence of the Lunex platform has been tracked through several distinct phases of growth. Initial evidence of the platform’s infrastructure appeared in June 2026, when security researcher Luke Wilkinson of BlueTeamCoolTeam identified six active command-and-control (C2) panels distributed across the U.S., Finland, Germany, the Netherlands, and Ukraine.
Since that time, the operation has undergone a significant expansion. Current data indicates the existence of at least 28 unique C2 panels operating across 13 countries. The geographic distribution of these servers—now including Russia, the U.K., France, Turkey, and Bangladesh—suggests that Lunex is not the work of a single localized threat actor, but rather a robust commercial service being rented out to multiple cybercriminal groups. This rapid scaling, observed in a matter of only a few months, serves as a testament to the profitability and efficiency of the current MaaS business model.

Technical Deep Dive: The Persistence Mechanism
Once the Psychedelic Stealer is active, it establishes a foothold that is remarkably difficult to remediate. The malware employs a 13,200-byte PowerShell script embedded in the binary’s .rdata section. This script implements the Chrome Native Messaging protocol, allowing the malware to operate within the context of the browser process.
Furthermore, the malware manipulates Chrome Secure Preferences to inject a malicious browser extension. By granting this extension extensive permissions—including access to cookies, history, bookmarks, and even script execution—the attackers gain near-total control over the victim’s web-browsing environment. Because the Native Messaging Host (NMH) survives system reboots and binary deletion, traditional cleanup methods are often insufficient, necessitating a deep-level forensic approach to fully excise the infection.
Broader Implications for Cybersecurity
The shift toward MaaS platforms like Lunex represents a significant challenge for both enterprise and individual security. By lowering the barrier to entry for novice attackers, these platforms allow for the rapid deployment of high-level capabilities, such as kernel-level evasion, that were once the sole purview of state-sponsored groups or advanced persistent threats (APTs).
The findings from this campaign also highlight the persistence of vulnerabilities in third-party drivers. As long as signed but vulnerable drivers remain authorized by the operating system, attackers will continue to exploit the "Bring Your Own Vulnerable Driver" technique. The fact that the industry has struggled to effectively curate and enforce a comprehensive blocklist for these drivers suggests that this attack vector will remain a staple of malicious toolkits for the foreseeable future.

Analysis of Attacker Motivation and Attribution
The composition of the Lunex panel suggests the involvement of a Russian-speaking developer or development collective. The interface and underlying code structure are consistent with other successful MaaS offerings in the Eastern European cybercrime sphere. The expansion of the infrastructure into diverse, non-traditional regions for C2 hosting—such as Bangladesh and Turkey—further indicates a decentralized operation designed to maximize resilience against law enforcement intervention.
Moreover, the versatility of the Lunex infrastructure is becoming increasingly apparent. Recent discoveries of phishing domains resolved through Turkey-based panels demonstrate that the platform is not merely limited to credential theft. Operators are now integrating brand impersonation and large-scale phishing campaigns into the same ecosystem, effectively turning Lunex into a "one-stop-shop" for illicit digital activity.
Mitigating the Threat
For organizations looking to defend against this evolving threat, reliance on traditional signature-based detection is clearly inadequate. Security professionals recommend a multi-layered defense strategy:
- Endpoint Hardening: Implementing strict policies regarding the loading of third-party drivers and utilizing the latest Windows Defender Application Control (WDAC) policies can help mitigate BYOVD risks.
- Behavioral Monitoring: Organizations should prioritize the detection of anomalous PowerShell execution and unexpected modifications to browser configuration files, which are key indicators of a Lunex infection.
- User Education: Given that the infection chain relies heavily on social engineering (the fake ClickFix verification), training employees to recognize and report suspicious "verification" prompts is a critical, if fundamental, line of defense.
- Infrastructure Hygiene: Regularly auditing and patching external-facing websites is essential. As seen in this campaign, compromised legitimate websites are the primary entry point for the attack.
As the Lunex platform continues to evolve, the distinction between "commodity" malware and advanced cyber-espionage tools continues to blur. The ability of the Psychedelic Stealer to operate with impunity at the kernel level demonstrates that even the most robust security environments are susceptible to sophisticated supply chain and driver-based exploits. Future industry efforts must focus on more rigorous vetting of driver signatures and a more dynamic approach to neutralizing kernel-mode threats before they can gain a foothold.
