The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

In September 2026, cybersecurity researchers discovered Lunex Stealer (also known as Psychedelic Stealer), a sophisticated malware-as-a-service platform targeting Ukrainian-speaking users through compromised websites using fake CAPTCHA verification. The attack leverages a vulnerable AMD Radeon driver (CVE-2023-20598) via bring-your-own-vulnerable-driver (BYOVD) technique to disable security monitoring while maintaining process visibility. The stealer extracts credentials from seven Chromium-based browsers, cryptocurrency wallets, and establishes persistent remote filesystem access through Chrome native messaging hosts. The Lunex platform has expanded rapidly since June 2026, with 28 unique command-and-control panels identified across 13 countries, demonstrating active development and distribution among multiple criminal groups. This incident represents a significant evolution in information stealer tactics, combining legitimate driver abuse with browser-based persistence mechanisms to evade detection while maintaining long-term access to victim systems.

Why This Matters Now

The abuse of legitimate but vulnerable drivers to blind security tools while keeping them running represents a sophisticated evasion technique that bypasses traditional EDR detection, making this threat particularly relevant as organizations face increasingly stealthy information stealing campaigns.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Lunex uses a vulnerable AMD driver to perform kernel callback zeroing, which blinds security products while keeping them running, making detection more difficult than traditional process termination methods.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely limit this browser-focused credential theft by constraining lateral movement and reducing blast radius through segmented network access controls. While initial compromise through fake CAPTCHA pages would still occur, the stealer's reach across network segments and external communication channels would face significant restrictions.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Initial browser-based compromise would likely still succeed, but CNSF visibility could reduce the malware's ability to establish comprehensive network reconnaissance and limit its understanding of available attack surfaces across cloud workloads.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Kernel-level privilege escalation would likely still occur on the compromised endpoint, but zero trust segmentation could significantly limit the stealer's ability to leverage elevated privileges for accessing segmented network resources and cloud workloads beyond the local system.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement attempts would likely face significant restrictions as east-west traffic controls could prevent the stealer from reaching additional systems or cloud workloads, limiting its expansion beyond the initially compromised browser environment and local filesystem.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: C2 communication establishment would likely be constrained through enhanced network monitoring and policy enforcement, potentially limiting the stealer's ability to maintain persistent command channels and reducing the effectiveness of the native messaging host bridge.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration activities would likely face significant constraints as egress controls could limit unauthorized outbound data transfers, potentially reducing the volume of stolen credentials and cryptocurrency wallet data successfully transmitted to attacker infrastructure.

Impact (Mitigations)

Browser-level compromise would likely persist with continued access to local credentials and browsing data, though the overall impact scope would be significantly reduced due to network segmentation limiting access to additional enterprise resources and cloud workloads.

Impact at a Glance

Affected Business Functions

  • Credential Management Systems
  • Browser Security Controls
  • Cryptocurrency Wallet Security
  • Endpoint Detection and Response
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Browser credentials from 7 Chromium-based browsers, cryptocurrency wallet data from 9 different wallets including MetaMask and hardware wallets, session cookies, browser history, bookmarks, and persistent filesystem access through compromised browser extensions

Recommended Actions

  • • Implement Egress Security & Policy Enforcement to detect and block unauthorized outbound communications to attacker C2 infrastructure like 193.178.159[.]128
  • • Deploy Zero Trust Segmentation with identity-based policies to prevent kernel-level driver exploitation from accessing sensitive browser and wallet data across different security contexts
  • • Enable Encrypted Traffic (HPE) controls to ensure credential and cryptocurrency wallet data exfiltration attempts are protected through high-performance encryption of data in transit
  • • Activate Multicloud Visibility & Control capabilities to detect anomalous browser extension installations and suspicious automation activities through centralized policy enforcement
  • • Configure Threat Detection & Anomaly Response to baseline normal browser behavior and alert on covert tools like malicious native messaging hosts and unauthorized PowerShell execution patterns

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image