Malware

Lunex malware platform uses Psychedelic Stealer via compromised Ukrainian sites

A new malware campaign is distributing the Psychedelic Stealer information stealer through compromised Ukrainian websites, employing a sophisticated four-stage attack chain, according to Ontinue. This activity is part of a broader malware-as-a-service (MaaS) platform known as Lunex, based on information published by The Hacker News.

The attack chain begins with a fake CAPTCHA page, leading to the deployment of a fully-featured command-and-control (C2) agent. The Psychedelic Stealer targets Ukrainian-speaking users, extracting credentials from seven Chromium-based browsers and cryptocurrency wallets. It establishes persistent remote filesystem access via a PowerShell-based Native Messaging Host. The infection utilizes bogus MSI installers and a loader called LunexLoader, which bypasses User Account Control (UAC) and employs a bring your own vulnerable driver (BYOVD) attack for defense evasion. Specifically, it exploits a vulnerable AMD Radeon Software driver (PDFWKRNL.sys) susceptible to CVE-2023-20598 to escalate privileges and blind security processes.

The Lunex MaaS platform, first documented in June 2026, has expanded significantly, with 28 identified C2 panels across 13 countries, indicating active growth and use by multiple threat actors. The platform's capabilities extend to phishing and brand impersonation, with one panel resolving to five phishing domains.

Source: The Hacker News

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Adware

You can skip this ad in 5 seconds