**The Rise of Lunex: Inside the Psychedelic Stealer’s Four-Stage Assault on Ukrainian Users**
Cybersecurity researchers have uncovered a highly advanced malware ecosystem known as Lunex, which is actively targeting Ukrainian-speaking internet users. At the center of this ecosystem sits the Psychedelic Stealer—also tracked as LunexStealer—a fully-featured information-stealing trojan delivered through a meticulously engineered, four-stage attack chain designed to bypass modern defenses and exfiltrate sensitive data.
The infection sequence begins with a deceptive social engineering tactic, often disguised as a Cloudflare verification check. Unsuspecting users are prompted to execute a bogus MSI installer, which introduces the first piece of the puzzle: a custom loader known as LunexLoader. This loader is engineered to execute a series of privilege escalation and defense-evasion maneuvers. It bypasses Windows User Account Control (UAC) using the CMSTPLUA COM object and subsequently deploys a Bring Your Own Vulnerable Driver (BYOVD) attack. By exploiting a flaw in an AMD Radeon Software kernel-mode driver—specifically the PDFWKRNL.sys file susceptible to CVE-2023-20598—the malware achieves the highest system privileges.
Rather than crashing security tools, the attackers employ a quieter, more insidious method known as PDB-guided kernel callback zeroing. This approach leaves antivirus and endpoint detection products running on the victim’s machine but renders them blind to the ongoing compromise, allowing the malware to operate undetected. Once these defenses are neutralized, the final stage is executed: the deployment of the Psychedelic Stealer payload.
Upon installation, the stealer immediately begins harvesting sensitive data. It targets seven Chromium-based browsers, extracting saved credentials and session cookies from names like Google Chrome, Microsoft Edge, Brave, Yandex Browser, and Opera variants. Additionally, it enumerates and exfiltrates data from multiple cryptocurrency wallets—both desktop applications such as Bitcoin Core, Litecoin, Exodus, Atomic Wallet, and Electrum, and browser extensions including MetaMask, MetaMask Legacy, OKX Wallet, and SafePal Wallet.
To ensure it survives system reboots and browser restarts, the malware establishes multiple persistence mechanisms. These include a Registry Run key, a hidden scheduled task named “psychedelicloveUtils,” and a malicious Chrome Native Messaging Host (NMH). The NMH is supported by a 13,200-byte PowerShell script embedded within the malware’s binary, granting it extensive control over the victim’s file system. The script can list drive letters, read arbitrary files up to 524 megabytes, write data to any path, download files from the system, and execute remote programs. Furthermore, the stealer injects a rogue Chrome extension by manipulating browser secure preferences, demanding broad permissions over cookies, history, bookmarks, and tabs to grant the attacker complete visibility into the victim’s online behavior.
The Lunex platform itself is operated by a Russian-speaking development team, with command-and-control infrastructure spanning across 13 countries, including Russia, the United States, the United Kingdom, and Turkey. This rapid geographic expansion suggests the platform is either operated by a single large group or sold to multiple criminal organizations as a Malware-as-a-Service (MaaS). Some of these infrastructure panels have also been linked to phishing domains impersonating major brands, indicating that the ecosystem extends beyond simple credential theft to facilitate broader fraud and brand impersonation attacks.
**Conclusion**
The Psychedelic Stealer and its underlying Lunex platform represent a significant evolution in information-stealing malware. By combining social engineering with sophisticated driver exploitation and stealthy defense evasion, this threat poses a severe risk to both individual users and organizations, particularly those in the Ukrainian sector. The active expansion of its infrastructure underscores the critical need for robust cybersecurity practices, including rigorous patch management, browser extension auditing, and heightened awareness of social engineering tactics like fake CAPTCHA verifications.
**Frequently Asked Questions (FAQ)**
**Q1: What is the Psychedelic Stealer?**
A: The Psychedelic Stealer, also known as LunexStealer, is an information-stealing malware that forms part of the Lunex Malware-as-a-Service (MaaS) platform. It is specifically designed to extract browser credentials, session cookies, and cryptocurrency wallet data from compromised systems.
**Q2: How does the attack chain begin?**
A: The attack chain begins with a social engineering tactic known as ClickFix, often disguised as a Cloudflare security verification page. Victims are tricked into executing a bogus MSI installer, which delivers the initial malware loader that sets off the rest of the attack sequence.
**Q3: What makes the BYOVD technique used by this malware significant?**
A: The Bring Your Own Vulnerable Driver (BYOVD) technique is significant because it allows the malware to escalate privileges by loading a legitimate but flawed kernel driver into memory. In this case, it exploits a vulnerability in an AMD Radeon Software driver to gain system-level access, and its use as a precursor to an information stealer remains relatively rare.
**Q4: Which browsers and cryptocurrency wallets are targeted?**
A: The stealer targets seven Chromium-based browsers, including Google Chrome, Microsoft Edge, Brave, Yandex Browser, Opera, Opera GX, and Vivaldi. It also targets five desktop cryptocurrency wallets (such as Bitcoin Core, Litecoin, Exodus, Atomic Wallet, and Electrum) and four browser extension wallets (including MetaMask, OKX Wallet, and SafePal Wallet).
Thank you for reading



