The images in this article were generated with artificial intelligence. How we publish
A campaign for Ukrainian-speaking users is distributing a credentials thief baptized as Psychedelic Stealer through legitimate committed websites that lead to a false ClickFix check (a trick that imitates Cloudflare verification). Recent research attributed to the Ontinue firm describes this operation as a four-stage chain that finally delivers a command and control agent (C2) capable of extracting passwords, session cookies and cryptomoneda purse keys, as well as establishing persistent access to the file system through a native messaging bridge in the browser.
Confirmed facts: Ontinue documented that the intrusion begins with false CAPTCHA pages embedded by iframes in legitimate sites (several reported victims include small businesses and service centres). The attackers use fraudulent MSI installers that launch a charger called LunexLoader. This loader tries to avoid user account control (UAC) using the COM CMSTPLUA object, applies an evasion technique known as "bringing your own vulnerable driver" (BYOVD) to blind security mechanisms in the kernel and, after climbing privileges, download the final component - the thief - that Ontinue and others have identified as part of the MaaS platform called Lunex. Arctic Wolf Labs and other firms have complemented this technical and distribution landscape.

Technically, the BYOVD stage is central and deserves attention: Lunex abuses a kernel-mode controller for AMD Radeon Software ("PDFWKRNL.sys") vulnerable to CVE-2023-20598 to modify the kernel's callbacks and blind certain security processes without necessarily ending them, according to the research. The effect is that detection and response solutions can continue to appear as active but without real visibility of what happens in the system. The CVE and technical details of the controller are publicly registered in the vulnerability database (see CVE-2023-20598).
What it steals and how: the thief explores and exfiltrates credentials stored in seven Chromium-based browsers (including Chrome, Edge, Brave, Opera and Vivaldi), five desktop coins (Bitcoin Core, Litecoin, Exodus, Atomic, Electrum) and several extensions of purse (MetaMask, OKX, SafePal). In addition, LunexStealer installs persistence through a Registry Run key, a hidden scheduled task called PsychedelicloveUtils, and records a native Chrome (NMH) messaging host supported by a embossed PowerShell script (~ 13 KB) that implements the native messaging protocol on stdin / stdout. This NMH allows the attacker to list units, read and write files, download and run binaries from the context of the browser process, and survive restarts and removal of the main binary.
Confirmed is also that the Lunex platform operates as a service: there are multiple active C2 control panels in several countries and the same malware piece is known as both Psychedelic (binary name) and LunexStealer (part of the Lunex platform). Researchers have identified rapid expansion of temporary short window panels, suggesting that the product is sold to several groups or is being used by operators other than the initial developer. Arctic Wolf Labs documented the initial infections from compromised sites; Ontinue published the detailed technical analysis of the loader, the exploitation of the driver and the capabilities of the NMH and C2.
Real consequences for users and organizations: once a team is engaged, attackers can empty "hot" wallets, hijacking banking and email sessions, taking account control with cookies-based authentication, and maintaining persistent access without simple detection by EDRs that have been "blinded" by the BYOVD. Given the use of a vulnerable kernel-mode driver for climbing, the integrity of the system may be compromised at a level that makes it difficult to rely on surface remediation; when the kernel has been manipulated, the only safe way to ensure a clean system is, in many cases, to reinstall the operating system from a known source and / or to reimagine the equipment.
What is confirmed and what is still estimated: it is confirmed that Lunex uses the vulnerability of PDFWKRNL.sys and that the loader uses CMSTPLUA for UAC bypass; also the extent of the theft of credentials and coins according to technical reports is confirmed. It is an estimate - though reasonable - that the actor behind the panel can be Russian-speaking, based on metadata and patterns on the panels, and it is likely (but not publicly proven in all cases) that the platform is offered as a service to third parties, given the growth of panels and the variety of domains used for phishing.
What readers should do now: act with priority if your device could visit any of those compromised sites or installed a suspicious MSI. Specific and verifiable recommendations:
1) Make a commitment when there is clear evidence. If you detect unusual scheduled tasks likePsychedelicloveUtils, strange Run entries in the Register, new Chromium extensions not installed by you, known HTTP communications to C2, or exfiltration activity samples, consider the equipment as engaged at an advanced level.
2) Preservation and cleaning. Make a forensic backup (log, samples) before changing the system if you need to investigate. For recovery, the safest is full reimaging of the equipment and clean reinstallation of legitimate software; surface cleaning does not guarantee to eradicate kernel manipulations.
(3) Protect credentials and funds. Change passwords and activate 2FA from an uncompromised device. Move funds from hot wallets to cold wallets if there is a suspicion of engagement. Check critical API sessions and keys (custom wallets, exchanges) from secure accounts.
4) Review browsers and extensions. Remove unknown extensions, restore safe preferences and check Chrome Secure Preferences for modifications. Review browser profile files and persistent cookies. Install or run analysis with up-to-date security tools from a clean system.
5) Update controllers and blockages. Install AMD / OS updates that mitigate vulnerability CVE-2023-20598 and avoid loading unsigned or suspicious drivers. Consider driver blocking policies in corporate environments and monitor your safety platform provider's vulnerable driver control list.

(6) Organizational monitoring and mitigation. In corporate networks, look for engagement indicators in outgoing HTTP traffic, programmed tasks and changes in browser configuration in workstations. Spread suspicious machines and coordinate with security providers for the detection of BYOVD techniques and handling of kernel callbacks.
To expand the reading and verify the technical vulnerabilities mentioned above, see the public resources on the affected CVE and the analysis reports: the official CVE register is available in MITRE ( CVE-2023-20598), and private and public response teams have published summaries and analyses on their blogs, for example Arctic Wolf Labs and the technical materials of Ontinue ( ontinue.com).
Conclusion: The combination of fraudulent pages with a chain that includes BYOVD to blind protection in kernel mode and a persistent mechanism within the browser makes Lunex / Psychedelic a complex threat and persists as an example of how MaaS platforms amplify the scope of criminals. Prevention goes by updating and harden controllers and browsers, adopting credentials security practices and, in the face of minimal suspicion of commitment, considering the reimagination of the system and the migration of funds to cold purse.
Related
More news on the same subject.

GhostAction Campaign commits maintenance accounts and inserts workflows to exfilter secrets
Security researchers have re-detected a massive credentials theft campaign that exploits open source project maintainer accounts to insert malicious workflows in GitHub reposito...

Florida, Iowa, Montana and Nebraska sue TP-Link Systems for security and source of routers
On October 6, four State Attorney General filed complaints against TP- Link Systems in U.S. state courts - in addition to a previous Texas lawsuit - for business practices relat...

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...