A malware-as-a-service platform named Lunex is actively distributing the Psychedelic Stealer malware through a sophisticated attack chain targeting Ukrainian-speaking users. The operation exploits compromised Ukrainian websites combined with fake CAPTCHA verification pages mimicking Cloudflare checks to deceive victims into downloading malicious payloads.

Security researchers at Ontinue uncovered the four-stage attack chain and documented how Lunex operators abuse legitimate AMD display drivers to disable Windows security monitoring. This driver abuse technique represents a significant escalation in evasion capabilities. By leveraging signed AMD drivers, attackers bypass security controls that would normally detect and block malicious activity.

The attack begins when users visit compromised Ukrainian websites. Instead of accessing legitimate content, they encounter a fake CAPTCHA page styled to look like Cloudflare's verification interface. This social engineering technique exploits user familiarity with legitimate security checks. Users who interact with these fake pages receive malicious executables that appear legitimate to endpoint security tools.

Once installed, the malware performs multiple malicious functions. The primary objective centers on stealing browser credentials and stored authentication data. Attackers specifically target saved passwords, autofill information, and cached login tokens from Chromium-based browsers and Firefox. The theft of browser credentials grants attackers access to email accounts, financial services, and corporate systems, creating cascading compromise risks.

The driver abuse component elevates this threat substantially. Lunex operators deploy AMD display drivers as a privilege escalation and detection evasion vector. By running unsigned malware code through signed drivers, the malware achieves kernel-level access while appearing legitimate to security monitoring tools. This technique disables behavioral analysis, process monitoring, and other endpoint detection systems that rely on kernel-level visibility.

Lunex functions as a malware-as-a-service platform, meaning the operators lease the infrastructure and tooling to other cybercriminals. This business model accelerates threat distribution and reduces technical barriers for attackers lacking development expertise. Customers pay for access to the stealer functionality and delivery mechanisms, creating a profitable criminal enterprise.

The targeting of Ukrainian-speaking users aligns with broader threat actor patterns in Eastern Europe. Ukrainian organizations remain frequent targets due to geopolitical tensions and the concentration of technology workers managing valuable corporate systems. The use of compromised local websites increases infection likelihood, as victims trust established Ukrainian web properties.

Organizations and individuals should recognize several indicators of compromise. Unusual browser activity, unexpected password changes, and authentication failures on accounts with strong credentials suggest potential credential theft. Endpoint detection systems should monitor for suspicious AMD driver loading, unsigned kernel module execution, and processes disabling Windows Defender or Event Log services.

Defense recommendations include enabling credential guard on Windows 11 systems, which isolates credential storage from malware access. Multi-factor authentication on all critical accounts provides secondary defense against stolen passwords. Browser isolation technologies prevent malware execution from compromised web pages. Regular driver updates from official sources reduce exploitation of driver vulnerabilities.

Security teams should prioritize patching Windows systems, maintaining updated antivirus definitions, and deploying behavioral analysis tools that detect kernel-level injection attempts. The Lunex campaign demonstrates how modern malware combines multiple techniques, from social engineering through to kernel-level evasion, requiring defense-in-depth strategies rather than single-layer protections.