Attackers are chaining compromised Ukrainian business websites with a vulnerable AMD Radeon driver to deliver the Lunex malware-as-a-service platform, disabling security monitoring and stealing browser credentials at scale.[2][7][11] Researchers say the operation turns a routine Cloudflare-style verification page into the launchpad for a full-featured command-and-control agent targeting Ukrainian-speaking users.[2][4]
The campaign begins on legitimate Ukrainian sites that have been hijacked to host hidden iframes rendering bogus Cloudflare verification or CAPTCHA checks, a lure pattern previously dubbed “ClickFix.”[1][3][12] When visitors interact with the page, they are instructed to run a Windows Installer command that pulls down a malicious MSI package, masquerading as a verification or update step but in reality installing the Lunex loader.[3][10] Ontinue’s analysis indicates the infrastructure and lures are tailored for Ukrainian-speaking audiences, expanding an already active Psychedelic Stealer distribution network into a broader MaaS offering.[2][4]
Once the MSI runs, the loader identified as LunexLoader uses the CMSTPLUA COM object to bypass Windows User Account Control, then drops and loads a vulnerable kernel-mode driver, PDFWKRNL.sys, from AMD Radeon Software in a classic bring-your-own-vulnerable-driver (BYOVD) move.[2][7] That driver exposes the flaw tracked as CVE-2023-20598, which attackers exploit to gain elevated privileges and tamper with security processes while keeping them nominally running to avoid user suspicion.[2][7][11] Ontinue’s testing found that Microsoft’s Hypervisor-Protected Code Integrity and its vulnerable driver blocklist did not stop the specific driver variant used in the Lunex campaign, underscoring gaps in current BYOVD mitigations.[7][4]
With the driver in place and defenses effectively blinded, Lunex deploys a stealer component that harvests credentials and data from seven Chromium-based browsers, exfiltrates cryptocurrency wallets, and establishes persistent remote filesystem access through a PowerShell-based Native Messaging Host implanted in the victim’s browser.[4][10] The same chain culminates in a fully featured C2 agent, giving operators long-term remote control over infected systems and enabling follow-on theft of files and other sensitive data.[4][2] Reporting from industry analysts describes Lunex as a rentable platform used by multiple criminal groups, rather than a single actor’s bespoke toolset, expanding the potential reach of this technique.[11]
Psychedelic Stealer, first documented by Arctic Wolf Labs, is one of the payloads delivered in these ClickFix-style attacks, where adversaries compromise sites belonging to businesses such as a hair-treatment clinic, a scale-model manufacturer, a bookseller, a psychological facility, a tool retailer, and an automotive shop to insert the malicious iframe.[2][10][1] Earlier reporting on Psychedelic detailed how the fake Cloudflare page copies a Windows Installer command to the user’s clipboard and instructs them to paste it into the Run dialog, a social-engineering step that now appears to sit inside the broader Lunex MaaS ecosystem.[3][10]
For defenders, the Lunex activity highlights the continued utility of BYOVD attacks to neutralize endpoint protections and the risks of trusting familiar UX elements like Cloudflare verification prompts. Organizations should ensure AMD Radeon drivers are fully patched for CVE-2023-20598, tighten controls around MSI execution, and monitor for COM object abuse associated with CMSTPLUA-based UAC bypasses. Network and web security teams should also watch for anomalous iframes and unexpected “verification” workflows on trusted sites, treating them as potential indicators of compromise rather than routine friction on the way to legitimate content.
References
- ClickFix Campaign Abuses Trusted Websites to Deploy …
- Lunex Stealer Abuses AMD Driver to Disable Security …
- Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
- Vulnerability — Latest News, Reports & Analysis
- Lunex stealer abuses AMD driver to disable security …
- Malware — Latest News, Reports & Analysis | The Hacker News
- Security – Clarity Today
- Malware Archives – Security Affairs
