Executive Summary
In September 2026, cybersecurity researchers discovered Lunex Stealer (also known as Psychedelic Stealer), a sophisticated malware-as-a-service platform targeting Ukrainian-speaking users through compromised websites using fake CAPTCHA verification. The attack leverages a vulnerable AMD Radeon driver (CVE-2023-20598) via bring-your-own-vulnerable-driver (BYOVD) technique to disable security monitoring while maintaining process visibility. The stealer extracts credentials from seven Chromium-based browsers, cryptocurrency wallets, and establishes persistent remote filesystem access through Chrome native messaging hosts. The Lunex platform has expanded rapidly since June 2026, with 28 unique command-and-control panels identified across 13 countries, demonstrating active development and distribution among multiple criminal groups. This incident represents a significant evolution in information stealer tactics, combining legitimate driver abuse with browser-based persistence mechanisms to evade detection while maintaining long-term access to victim systems.
Why This Matters Now
The abuse of legitimate but vulnerable drivers to blind security tools while keeping them running represents a sophisticated evasion technique that bypasses traditional EDR detection, making this threat particularly relevant as organizations face increasingly stealthy information stealing campaigns.
Attack Path Analysis
Lunex Stealer initiated compromise through ClickFix-style fake CAPTCHA pages on compromised Ukrainian websites, escalated privileges using a vulnerable AMD driver (CVE-2023-20598) to disable security monitoring, established persistence through multiple mechanisms including Chrome native messaging host, maintained C2 communication over HTTP to panel at 193.178.159[.]128, exfiltrated browser credentials and cryptocurrency wallet data from seven Chromium browsers and multiple wallets, and achieved impact through persistent filesystem access and complete browser control via injected malicious extensions.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers compromised legitimate Ukrainian websites to inject iframe elements serving ClickFix-style fake CAPTCHA pages, delivering malicious MSI installers to unsuspecting users
Related CVEs
CVE-2023-20598
CVSS 7.8A privilege escalation vulnerability in AMD Radeon Software PDFWKRNL.sys driver allows local attackers to execute arbitrary code with kernel privileges through improper validation of kernel-mode requests.
Affected Products:
AMD Radeon Software PDFWKRNL.sys – < 23.11.1
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
Subvert Trust Controls: Code Signing Policy Modification
Exploitation for Privilege Escalation
Impair Defenses: Disable or Modify Tools
Credentials from Password Stores: Credentials from Web Browsers
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Process Injection
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Engineering Techniques for Secure Development
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – Identification and Classification of ICT Risk
Control ID: Article 8
CISA ZTMM 2.0 – Asset Management
Control ID: ED.AM.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21.2.a
GDPR – Security of Processing
Control ID: Article 32
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Banking/Mortgage
Lunex Stealer's credential theft from Chromium browsers and cryptocurrency wallets directly threatens online banking systems and financial data security protocols.
Computer Software/Engineering
BYOVD attacks exploiting AMD driver vulnerabilities and browser extension manipulation create significant risks for software development environments and security tools.
Financial Services
Information stealer targeting cryptocurrency wallets and browser credentials poses severe risks to financial service providers and client asset protection measures.
Computer/Network Security
EDR neutralization through kernel callback zeroing and security tool blinding represents critical threats to cybersecurity operations and incident response capabilities.
Sources
- Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentialshttps://thehackernews.com/2026/09/lunex-stealer-abuses-amd-driver-to.htmlVerified
- AMD Security Bulletin AMD-SB-6009: CVE-2023-20598https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6009.htmlVerified
- Lunex Unmasked: A New Information Stealer Deployed Through BYOVDhttps://www.ontinue.com/resource/lunex-unmasked-a-new-information-stealer-deployed-through-byovd/Verified
- LOLDrivers Project - PDFWKRNL.syshttps://github.com/magicsword-io/LOLDriversVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely limit this browser-focused credential theft by constraining lateral movement and reducing blast radius through segmented network access controls. While initial compromise through fake CAPTCHA pages would still occur, the stealer's reach across network segments and external communication channels would face significant restrictions.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial browser-based compromise would likely still succeed, but CNSF visibility could reduce the malware's ability to establish comprehensive network reconnaissance and limit its understanding of available attack surfaces across cloud workloads.
Control: Zero Trust Segmentation
Mitigation: Kernel-level privilege escalation would likely still occur on the compromised endpoint, but zero trust segmentation could significantly limit the stealer's ability to leverage elevated privileges for accessing segmented network resources and cloud workloads beyond the local system.
Control: East-West Traffic Security
Mitigation: Lateral movement attempts would likely face significant restrictions as east-west traffic controls could prevent the stealer from reaching additional systems or cloud workloads, limiting its expansion beyond the initially compromised browser environment and local filesystem.
Control: Multicloud Visibility & Control
Mitigation: C2 communication establishment would likely be constrained through enhanced network monitoring and policy enforcement, potentially limiting the stealer's ability to maintain persistent command channels and reducing the effectiveness of the native messaging host bridge.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration activities would likely face significant constraints as egress controls could limit unauthorized outbound data transfers, potentially reducing the volume of stolen credentials and cryptocurrency wallet data successfully transmitted to attacker infrastructure.
Browser-level compromise would likely persist with continued access to local credentials and browsing data, though the overall impact scope would be significantly reduced due to network segmentation limiting access to additional enterprise resources and cloud workloads.
Impact at a Glance
Affected Business Functions
- Credential Management Systems
- Browser Security Controls
- Cryptocurrency Wallet Security
- Endpoint Detection and Response
Estimated downtime: N/A
Estimated loss: N/A
Browser credentials from 7 Chromium-based browsers, cryptocurrency wallet data from 9 different wallets including MetaMask and hardware wallets, session cookies, browser history, bookmarks, and persistent filesystem access through compromised browser extensions
Recommended Actions
Key Takeaways & Next Steps
- • Implement Egress Security & Policy Enforcement to detect and block unauthorized outbound communications to attacker C2 infrastructure like 193.178.159[.]128
- • Deploy Zero Trust Segmentation with identity-based policies to prevent kernel-level driver exploitation from accessing sensitive browser and wallet data across different security contexts
- • Enable Encrypted Traffic (HPE) controls to ensure credential and cryptocurrency wallet data exfiltration attempts are protected through high-performance encryption of data in transit
- • Activate Multicloud Visibility & Control capabilities to detect anomalous browser extension installations and suspicious automation activities through centralized policy enforcement
- • Configure Threat Detection & Anomaly Response to baseline normal browser behavior and alert on covert tools like malicious native messaging hosts and unauthorized PowerShell execution patterns



