Lunex Turns a Flawed AMD Driver Into a Stealth Layer for Browser and Wallet Theft

Lunex campaign uses fake Cloudflare checks and MSI installers to deploy LunexLoader, abuse AMD driver CVE-2023-20598, and steal browser and wallet data.

Lunex Turns a Flawed AMD Driver Into a Stealth Layer for Browser and Wallet Theft
Malware

Illustrative image generated with AI

Listen to this articleAudio edition · 10 min

Compromised websites funnel victims into a four-stage infection chain

A recent malware campaign targeting Ukrainian-speaking users combines compromised websites, fraudulent software installers, kernel-level defense evasion, and persistent browser access.

The operation begins with legitimate Ukrainian websites altered to load a malicious iframe. Visitors encounter a ClickFix-style page masquerading as a Cloudflare verification prompt, which directs them toward bogus MSI installers.

Arctic Wolf Labs separately observed Psychedelic Stealer being distributed through compromised sites belonging to varied organizations, including a hair-treatment clinic, a model manufacturer, a specialist bookseller, a psychological facility, a tool retailer, and an automotive retailer. The diversity of those sites suggests that operators are exploiting available web infrastructure rather than focusing on one business sector.

The installers deploy LunexLoader, which prepares the system for the final information-stealing payload. Its responsibilities include bypassing Windows User Account Control, loading a vulnerable kernel driver, interfering with security tooling, and retrieving the stealer.

Naming can be confusing. Psychedelic Stealer is the malware executing on infected computers, while Lunex refers to the broader malware-as-a-service platform sold to multiple criminal groups. The payload is also called LunexStealer in some reporting.

LunexLoader abuses CMSTPLUA before reaching the Windows kernel

The loader first attempts to bypass User Account Control through the CMSTPLUA COM object. It then applies a bring-your-own-vulnerable-driver, or BYOVD, technique using PDFWKRNL.sys, a kernel-mode driver associated with AMD Radeon Software.

BYOVD attacks do not necessarily require an attacker to develop a malicious driver. Instead, malware brings a legitimately signed but vulnerable driver onto the victim’s computer and exploits its privileged kernel access. A valid signature can make that component appear less suspicious to Windows and some endpoint controls.

The driver used by Lunex is affected by CVE-2023-20598, an improper privilege management vulnerability tracked as CWE-269. It carries a CVSS v3 score of 7.8, with the vector:

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

The flaw may allow an authenticated attacker with local, low-level privileges to craft an IOCTL request and gain I/O control over arbitrary hardware ports or physical addresses. Successful exploitation could enable arbitrary code execution with severe confidentiality, integrity, and availability consequences.

Lunex uses this access to elevate privileges and interfere with security-related processes. Rather than simply terminating those processes, which could trigger alerts or reveal the intrusion, the malware reportedly uses debugging-symbol information from PDB files to locate and zero kernel callbacks.

This approach can leave security processes visibly running while reducing their ability to receive or act on relevant system events. The result is a quieter form of impairment.

The affected AMD software and hardware listed by NVD

The NVD information identifies AMD Radeon Software versions earlier than 23.9.2 as affected. It also lists the following Radeon products, with their version fields represented as -:

  • AMD Radeon RX 5300
  • AMD Radeon RX 5300 XT
  • AMD Radeon RX 5300M
  • AMD Radeon RX 5500
  • AMD Radeon RX 5500 XT
  • AMD Radeon RX 5500M
  • AMD Radeon RX 5600
  • AMD Radeon RX 5600 XT
  • AMD Radeon RX 5600M
  • AMD Radeon RX 5700
  • AMD Radeon RX 5700 XT

No vendor remediation advisory or campaign-specific patch instructions have been disclosed. The available vulnerability information only establishes the affected software threshold of amd radeon software < 23.9.2.

The supplied NVD record does not establish whether CVE-2023-20598 is included in CISA’s Known Exploited Vulnerabilities catalog, and no CISA remediation deadline is available. There is also no ransomware-use flag in the available data.

The driver hash associated with this campaign had reportedly appeared in the LOLDrivers project since March 2026. Despite that prior documentation, testing found that neither Hypervisor-Protected Code Integrity, commonly called HVCI, nor Microsoft’s current Vulnerable Driver Blocklist prevented the specific PDFWKRNL.sys variant from loading.

Those controls should therefore not be treated as sufficient detection or prevention measures for this infection chain.

Psychedelic Stealer targets browsers and cryptocurrency wallets

After the loader weakens host defenses, the stealer communicates over HTTP with a Lunex control panel at:

193.178.159[.]128

Its collection logic targets credentials and other stored information from seven Chromium-based browsers:

  • Google Chrome
  • Microsoft Edge
  • Brave
  • Yandex Browser
  • Opera
  • Opera GX
  • Vivaldi

The malware also searches for five desktop cryptocurrency wallets: Bitcoin Core, Litecoin, Exodus, Atomic Wallet, and Electrum. Four browser-extension wallets are enumerated as well: MetaMask, MetaMask Legacy, OKX Wallet, and SafePal Wallet.

That combination gives operators access to several categories of valuable information. Browser data may expose authenticated sessions, saved credentials, browsing records, and account information, while wallet theft can lead directly to cryptocurrency loss.

Lunex additionally modifies Chrome Secure Preferences to install a malicious extension. Its requested permissions include cookies, browsing history, bookmarks, tabs, storage, proxy configuration, scripting, declarativeNetRequest, and access to all HTTP and HTTPS addresses.

These permissions provide extensive visibility into browser activity and the ability to alter how web requests are processed.

A native-messaging backdoor can survive removal of the stealer

The malware establishes persistence through several independent mechanisms. These include a Registry Run key, a hidden scheduled task named psychedelicloveUtils, and a Chrome native-messaging host.

The native-messaging component is particularly significant. It is implemented through a 13,200-byte PowerShell script stored in the malware’s .rdata section and communicates over standard input and output from within Chrome’s process context.

The mechanism reportedly remains functional after the main stealer executable is deleted, as well as after system reboots and browser restarts. Removing only the visible payload may therefore leave a capable remote-access channel behind.

The script supports six commands:

  • list_drives enumerates drive letters from C through Z.
  • list_dir lists directory contents and file sizes.
  • read_file reads arbitrary files in 512 KB chunks, supporting files up to 524 MB.
  • write writes attacker-controlled data to an arbitrary path.
  • download retrieves files from the compromised system.
  • run executes arbitrary programs.

Together, those functions turn the browser integration into more than a persistence mechanism. It can browse the filesystem, collect large files, place additional payloads, and execute programs.

Defenders should hunt beyond the initial MSI installer

Organizations investigating possible exposure should look for the entire chain rather than relying on detection of Psychedelic Stealer alone. Priority indicators and behaviors include:

  • Unexpected loading of PDFWKRNL.sys, especially from nonstandard directories.
  • IOCTL activity involving the vulnerable driver.
  • Suspicious use of the CMSTPLUA COM object.
  • The hidden scheduled task psychedelicloveUtils.
  • Unfamiliar Registry Run-key entries.
  • Unauthorized Chrome native-messaging-host registrations.
  • PowerShell operating through Chrome’s native-messaging interfaces.
  • Changes to Chrome Secure Preferences or unexplained extensions with broad permissions.
  • HTTP traffic to 193.178.159[.]128.
  • MSI installers obtained through supposed Cloudflare verification pages.

Defenders should also inspect for contact with the phishing domains linked to a Lunex panel hosted in Turkey:

  • account-sams-club[.]com
  • teamwork-recover-password[.]com
  • namshi-uae[.]com
  • whatsappbusineses[.]com
  • ibraq-perfumes[.]com

The first cited cybersecurity reference to Lunex appeared in June 2026, when researcher Luke Wilkinson identified six active command-and-control panels across the United States, Finland, Germany, the Netherlands, and Ukraine. Subsequent research found 28 unique panels in 13 countries, including Russia, the United States, the United Kingdom, the Netherlands, France, Germany, Turkey, and Bangladesh.

Incident response should include removal of the scheduled task, Run-key persistence, malicious extension, and native-messaging host—not only the original executable. Browser sessions and stored credentials should be treated as potentially compromised, while affected cryptocurrency wallets may require separate containment and asset-transfer procedures.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →