malware
Published 2026-09-24
Verified 2026-09-27

Lunex MaaS / Psychedelic Stealer (Ontinue 24 Sep + THN 26 Sep): ClickFix MSI → BYOVD AMD PDFWKRNL.sys (CVE-2023-20598) → Chromium NMH stealer

UPDATE 26 Sep 2026: Ontinue CDC (published 24 September 2026; The Hacker News 26 Sep) reverse-engineers the four-stage chain behind the Ukrainian ClickFix campaign Arctic Wolf named Psychedelic Stealer. Ontinue identifies Lunex as the underlying malware-as-a-service platform (Russian-language panel UI; 28 panels across 13 countries vs six in June 2026 BlueTeamCoolTeam OSINT) and Psychedelic / LunexStealer as the same endpoint payload. Delivery remains fake Cloudflare CAPTCHA → msiexec MSI (elita.msi / siblings from uasputnik[.]com) installing per-user “Vertification” by “Internal Software”. Loader (config.exe / psychedelic.exe) uses CMSTPLUA COM elevation (no UAC) then BYOVD: loads AMD Radeon / USB-C PD firmware driver PDFWKRNL.sys (Authenticode-signed; susceptible to CVE-2023-20598) and zeroes kernel callbacks (PDB-guided via Microsoft Symbol Server) so EDR stays running but blind — Ontinue notes neither HVCI nor the current Microsoft Vulnerable Driver Blocklist blocked the variant (hash in LOLDrivers since March 2026). Final stage steals seven Chromium browsers + wallets, injects a Chrome extension via Secure Preferences, and persists a PowerShell Native Messaging Host (panel C2 incl. 193.178.159[.]128). Arctic Wolf first documented the Ukrainian-site ClickFix lure 24 Sep (desk primary); Ontinue supplies the Lunex platform / BYOVD depth. No new CVE beyond CVE-2023-20598 on the abused AMD driver. Primary update: Ontinue; wire: THN 26 Sep; original lure: Arctic Wolf.

Product
Lunex MaaS / Psychedelic Stealer (Windows); abused AMD PDFWKRNL.sys (CVE-2023-20598)
Versions
n/a (malicious MSI/EXE; staging uasputnik.com; C2 panels incl. 193.178.159.128 per Ontinue / THN; Arctic Wolf also noted 107.175.82.242:9000). Driver: PDFWKRNL.sys variant catalogued in LOLDrivers.
Exploited in Australia?
unknown
Patch to
Never paste Cloudflare/CAPTCHA commands into Win+R; block msiexec to untrusted hosts; enforce Microsoft Vulnerable Driver Blocklist + HVCI where compatible and still hunt PDFWKRNL.sys loads; alert on CMSTPLUA elevation + Symbol Server curls from non-dev hosts; hunt uasputnik.com / known Lunex panel IPs; rotate browser/wallet credentials after suspected paste-execution; scan partner web estates for injected Cloudflare iframes.

Primary: Ontinue — Lunex Unmasked: BYOVD information stealer (24 Sep 2026) · Vendor: Arctic Wolf Labs — Psychedelic Stealer ClickFix CAPTCHA (24 Sep 2026) · CVE: CVE-2023-20598 · The Hacker News — Lunex Stealer AMD BYOVD (26 Sep 2026)

tech identity network