Psychedelic Stealer is being spread through compromised Ukrainian websites using ClickFix-style Cloudflare verification lures as part of the Lunex malware-as-a-service platform. The campaign uses a four-stage attack chain with a vulnerable AMD driver, stealthy security evasion, browser credential theft, wallet exfiltration, and persistent remote access via a Chrome Native Messaging Host. #PsychedelicStealer #Lunex #PDFWKRNLsys #CVE202320598
Keypoints
- Psychedelic Stealer is delivered through fake CAPTCHA pages on compromised Ukrainian websites.
- The malware is part of the Lunex malware-as-a-service platform.
- LunexLoader uses UAC bypass and BYOVD techniques to disable security defenses.
- The stealer targets browser passwords, session cookies, and cryptocurrency wallets.
- Lunex also supports persistence, remote filesystem access, and phishing domains.
Read More: https://thehackernews.com/2026/09/lunex-stealer-abuses-amd-driver-to.html