INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ATTENTION: This report is based on previous data. New intelligence sources have been linked and the Executive Summary and Mitigations need to be re-synthesized.
Lunex Uses BYOVD to Deploy Persistent Stealer Against Russian Companies
| 2026-10-08 02:02 LOW HIGH RANSOMWARE & EXTORTION MALWARE & BOTNETS
Executive Summary
AI-generated
On October 6, 2026, the Lunex Malware-as-a-Service platform targeted Ukrainian users through fake CAPTCHA lures, exploiting AMD's vulnerable PDFWKRNL.sys driver (CVE-2023-20598) to disable endpoint security products. The attack affected seven Chromium-based browsers and multiple cryptocurrency wallets, with a total of 7 countries being targeted in Ukraine. The attackers used the BYOVD technique to manipulate security controls, deploying LunexStealer to harvest credentials while establishing persistent C2 access through registry keys, scheduled tasks, and Native Messaging Host registrations. This mechanism survives deletion of the primary executable, providing continued filesystem access and remote execution capabilities.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2023-20598 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2023-20598CVE-2023-20598
Target & Sectors
BENELUX
BENELUX
CENTRAL_ASIA
CENTRAL_ASIA
DACH
DACH
cryptocurrencycryptocurrency
retailretail
logisticslogistics
manufacturingmanufacturing
Incident Timeline
March 2026
Microsoft's Vulnerable Driver Blocklist failed to prevent the loading of a specific PDFWKRNL.sys variant, which was previously catalogued in the LOLDrivers project since March 2026.
Click on any entity below to view its context and source!
organisation
Microsoft
"Validated testing demonstrated that neither HVCI nor the current Microsoft Vulnerable Driver Blocklist prevents the specific PDFWKRNL.sys variant used in this chain from loading, a gap that persists despite the driver hash being catalogued in the LOLDrivers project since March 2026."
organisation
LOLDrivers
"Validated testing demonstrated that neither HVCI nor the current Microsoft Vulnerable Driver Blocklist prevents the specific PDFWKRNL.sys variant used in this chain from loading, a gap that persists despite the driver hash being catalogued in the LOLDrivers project since March 2026."
June 2026
Threat actors used Lunex Stealer's command-and-control panels to target multiple countries, including Ukraine and Russia.
Click on any entity below to view its context and source!
target_region
Ukraine
The earliest reference to Lunex in cybersecurity literature dates back to June 2026, when BlueTeamCoolTeam's Luke Wilkinson
identified
six active Lunex Stealer's command-and-control (C2) panels across the U.S., Finland, Germany, the Netherlands, and Ukraine.
source_region
Finland
The earliest reference to Lunex in cybersecurity literature dates back to June 2026, when BlueTeamCoolTeam's Luke Wilkinson
identified
six active Lunex Stealer's command-and-control (C2) panels across the U.S., Finland, Germany, the Netherlands, and Ukraine.
source_region
Germany
The earliest reference to Lunex in cybersecurity literature dates back to June 2026, when BlueTeamCoolTeam's Luke Wilkinson
identified
six active Lunex Stealer's command-and-control (C2) panels across the U.S., Finland, Germany, the Netherlands, and Ukraine.
target_region
Netherlands
The earliest reference to Lunex in cybersecurity literature dates back to June 2026, when BlueTeamCoolTeam's Luke Wilkinson
identified
six active Lunex Stealer's command-and-control (C2) panels across the U.S., Finland, Germany, the Netherlands, and Ukraine.
general_metric
28 panels
Analysis of the Lunex panel points to a Russian-speaking developer or development team, with 28 unique panels identified across 13 countries, marking a major expansion from June 2026.
general_metric
13 countries
Analysis of the Lunex panel points to a Russian-speaking developer or development team, with 28 unique panels identified across 13 countries, marking a major expansion from June 2026.
source_region
Russian Federation
Analysis of the Lunex panel points to a Russian-speaking developer or development team, with 28 unique panels identified across 13 countries, marking a major expansion from June 2026.
organisation
Analysis of the
Analysis of the Lunex panel points to a Russian-speaking developer or development team, with 28 unique panels identified across 13 countries, marking a major expansion from June 2026.
2026/10/06
Threat actors used a vulnerable AMD Radeon Software driver (CVE-2023-20598) to escalate privileges and blind security-related processes, then deployed the LunexStealer malware through compromised websites using ClickFix-style Cloudflare verification checks.
Click on any entity below to view its context and source!
organisation
The Lunex
The Lunex Malware-as-a-Service platform targets Ukrainian users through fake CAPTCHA lures, deploying a sophisticated loader that exploits AMD's vulnerable PDFWKRNL.sys driver (CVE-2023-20598) to disable endpoint security products.
organisation
CAPTCHA
The Lunex Malware-as-a-Service platform targets Ukrainian users through fake CAPTCHA lures, deploying a sophisticated loader that exploits AMD's vulnerable PDFWKRNL.sys driver (CVE-2023-20598) to disable endpoint security products.
A sophisticated four-stage attack chain delivers the Lunex information stealer to Ukrainian-speaking users through fake CAPTCHA pages.
"The attack chain begins with a fake CAPTCHA page and culminates in the deployment of a fully-featured C2 agent," Ontinue threat researcher Rhys Downing
said
in a technical report.
organisation
AMD
The Lunex Malware-as-a-Service platform targets Ukrainian users through fake CAPTCHA lures, deploying a sophisticated loader that exploits AMD's vulnerable PDFWKRNL.sys driver (CVE-2023-20598) to disable endpoint security products.
The malware employs Bring Your Own Vulnerable Driver (BYOVD) techniques using AMD's PDFWKRNL.sys to disable kernel-level security monitoring before deploying the final payload.
organisation
ClickFix
The
Psychedelic Stealer
malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called
Lunex
.
organisation
Cloudflare
The
Psychedelic Stealer
malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called
Lunex
.
organisation
CVE-2023-20598
Lunex takes advantage of a vulnerable kernel-mode driver for AMD Radeon Software ("PDFWKRNL.sys"), which is
susceptible
to
CVE-2023-20598
, to
escalate privileges
and blind security-related processes while keeping them running.
organisation
Lunex
Lunex takes advantage of a vulnerable kernel-mode driver for AMD Radeon Software ("PDFWKRNL.sys"), which is
susceptible
to
CVE-2023-20598
, to
escalate privileges
and blind security-related processes while keeping them running.
organisation
AMD Radeon
Lunex takes advantage of a vulnerable kernel-mode driver for AMD Radeon Software ("PDFWKRNL.sys"), which is
susceptible
to
CVE-2023-20598
, to
escalate privileges
and blind security-related processes while keeping them running.
infrastructure
Windows
The loader retrieves Windows kernel debugging symbols from Microsoft's Symbol Server to dynamically identify and zero security-related kernel callbacks, making the technique version-agnostic.
The infection makes use of bogus MSI installers delivered via ClickFix to trigger a series of actions, including delivering a loader dubbed LunexLoader that's designed to bypass User Account Control (UAC) on Windows using the CMSTPLUA COM object, leverage the bring your own vulnerable driver (
BYOVD
) attack for defense evasion, and finally download the stealer payload.
organisation
Microsoft
The loader retrieves Windows kernel debugging symbols from Microsoft's Symbol Server to dynamically identify and zero security-related kernel callbacks, making the technique version-agnostic.
organisation
MSI
The infection makes use of bogus MSI installers delivered via ClickFix to trigger a series of actions, including delivering a loader dubbed LunexLoader that's designed to bypass User Account Control (UAC) on Windows using the CMSTPLUA COM object, leverage the bring your own vulnerable driver (
BYOVD
) attack for defense evasion, and finally download the stealer payload.
organisation
LunexLoader
The infection makes use of bogus MSI installers delivered via ClickFix to trigger a series of actions, including delivering a loader dubbed LunexLoader that's designed to bypass User Account Control (UAC) on Windows using the CMSTPLUA COM object, leverage the bring your own vulnerable driver (
BYOVD
) attack for defense evasion, and finally download the stealer payload.
organisation
User Account Control
The infection makes use of bogus MSI installers delivered via ClickFix to trigger a series of actions, including delivering a loader dubbed LunexLoader that's designed to bypass User Account Control (UAC) on Windows using the CMSTPLUA COM object, leverage the bring your own vulnerable driver (
BYOVD
) attack for defense evasion, and finally download the stealer payload.
organisation
Lunex Uses
Lunex Uses BYOVD to Disable Security Monitoring and Deploy Persistent Stealer.
organisation
Disable Security Monitoring and
Lunex Uses BYOVD to Disable Security Monitoring and Deploy Persistent Stealer.
organisation
LunexStealer
After manipulating security controls, LunexStealer is deployed to harvest credentials from seven Chromium-based browsers and multiple cryptocurrency wallets while establishing persistent C2 access through registry keys, scheduled tasks, and Native Messaging Host registrations.
LunexStealer (aka Psychedelic Stealer) C2 Panel | Source: BlueTeamCoolTeam
It's worth noting that both Psychedelic Stealer and LunexStealer refer to the same component of the MaaS platform.
organisation
Chromium
After manipulating security controls, LunexStealer is deployed to harvest credentials from seven Chromium-based browsers and multiple cryptocurrency wallets while establishing persistent C2 access through registry keys, scheduled tasks, and Native Messaging Host registrations.
The stealer targets seven Chromium-based browsers, extracts credentials using custom SQLite parsers, exfiltrates cryptocurrency wallets, and establishes persistent access through PowerShell-based Chrome Native Messaging Hosts that survive binary deletion.
"The stealer extracts credentials and data from seven Chromium-based browsers, exfiltrates cryptocurrency wallets, and establishes persistent remote filesystem access through a PowerShell-based Native Messaging Host installed within the victim's browser.
organisation
C2 Panel
LunexStealer (aka Psychedelic Stealer) C2 Panel | Source: BlueTeamCoolTeam
It's worth noting that both Psychedelic Stealer and LunexStealer refer to the same component of the MaaS platform.
organisation
SQLite
The stealer targets seven Chromium-based browsers, extracts credentials using custom SQLite parsers, exfiltrates cryptocurrency wallets, and establishes persistent access through PowerShell-based Chrome Native Messaging Hosts that survive binary deletion.
organisation
Native Messaging Host
"The stealer extracts credentials and data from seven Chromium-based browsers, exfiltrates cryptocurrency wallets, and establishes persistent remote filesystem access through a PowerShell-based Native Messaging Host installed within the victim's browser.
organisation
PDB
The Lunex platform operates 28 command-and-control panels across 13 countries, features Russian-language operator interfaces, and demonstrates advanced engineering including PDB-guided kernel callback zeroing, custom encryption implementations, and direct syscall invocation.
"The BYOVD delivery chain, using PDB-guided kernel callback zeroing rather than process termination, represents a quieter approach to EDR neutralisation that leaves security products running but blind," Ontinue said.
data_breach
2026 September
LxBase RAT observed for the first time in attacks against Russian companies..
From July through September 2026, threat actors conducted mass phishing campaigns against Russian organizations in finance, engineering, manufacturing, energy, retail, agriculture, logistics, construction, and IT.
organisation
BYOVD
"The BYOVD delivery chain, using PDB-guided kernel callback zeroing rather than process termination, represents a quieter approach to EDR neutralisation that leaves security products running but blind," Ontinue said.
organisation
EDR
"The BYOVD delivery chain, using PDB-guided kernel callback zeroing rather than process termination, represents a quieter approach to EDR neutralisation that leaves security products running but blind," Ontinue said.
organisation
Lunex Unmasked
Lunex Unmasked: A New Information Stealer Deployed Through BYOVD.
data_breach
13,200 byte
"The host is backed by a 13,200-byte PowerShell script embedded in the .rdata section that implements the Chrome Native Messaging protocol over standard input and output," Downing said.
organisation
RAR
Attachments were RAR archives disguised with a `.tar` extension and contained obfuscated JavaScript loaders.
organisation
Disable Security Monitoring and Steal Browser
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials.
organisation
Google Chrome
Upon execution, LunexStealer communicates with the Lunex panel at 193.178.159[.]128 over HTTP to facilitate comprehensive information theft -
Steal credentials from Google Chrome, Microsoft Edge, Brave, Yandex Browser, Opera, Opera GX, and Vivaldi.
organisation
Microsoft Edge, Brave
Upon execution, LunexStealer communicates with the Lunex panel at 193.178.159[.]128 over HTTP to facilitate comprehensive information theft -
Steal credentials from Google Chrome, Microsoft Edge, Brave, Yandex Browser, Opera, Opera GX, and Vivaldi.
organisation
Opera GX
Upon execution, LunexStealer communicates with the Lunex panel at 193.178.159[.]128 over HTTP to facilitate comprehensive information theft -
Steal credentials from Google Chrome, Microsoft Edge, Brave, Yandex Browser, Opera, Opera GX, and Vivaldi.
organisation
NMH
Establish persistence using a Registry Run key, a hidden scheduled task named "psychedelicloveUtils," and register a
Chrome native-messaging bridge or host
(NMH) that allows the stealer to perform additional actions.
organisation
Chrome Secure Preferences
…write
, to write arbitrary data to any file path
download
, to download files from the system
run
, to execute arbitrary programs
What's more, LunexStealer injects a malicious Chrome extension by manipulating Chrome Secure Preferences and declares extensive permissions for cookies, history, bookmarks, tabs, storage, proxy, scripting, declarativeNetRequest, and all HTTP and HTTPS URLs.
data_breach
524 MB write
"
The PowerShell script supports six file system actions -
list_drives
, to enumerate all drive letters C through Z
list_dir
, to list directory contents with file sizes
read_file
, to read arbitrary files in 512 KB chunks and those up to 524 MB
write
, to write arbitrary data to any file path
download
, to download files from the system
run
, to execute arbitrary programs
Wha…
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
In Mode 2, the bogus verification page is shown only to Windows users who arrive at the site from search engine results and not more than twice in 12 hours.
Variant 2
, which attempts to bypass Windows account control (UAC), configures Microsoft Defender exclusions, leverages the legitimate-but-vulnerable AMD driver ("PDFWKRNL.sys") to blind security software, and then retrieves and runs LunexStealer from a remote server.
Its primary responsibility is to provide LUNARAXE with access to the Windows file system through a PowerShell-based Native Messaging Host.
CERT-UA is advising organizations to prohibit regular users from using the Windows Run dialog via group policies, restrict the installation of MSI packages by users without administrator rights, monitor for the execution of "msiexec.exe," enable blocking of vulnerable drivers via Microsoft's vulnerable driver blocklist, and limit the installation of browser extensions to allowlisted ones.
The loader retrieves Windows kernel debugging symbols from Microsoft's Symbol Server to dynamically identify and zero security-related kernel callbacks, making the technique version-agnostic.
The infection makes use of bogus MSI installers delivered via ClickFix to trigger a series of actions, including delivering a loader dubbed LunexLoader that's designed to bypass User Account Control (UAC) on Windows using the CMSTPLUA COM object, leverage the bring your own vulnerable driver (
BYOVD
) attack for defense evasion, and finally download the stealer payload.
Metrics
infrastructure
Microsoft Office
Affected Product
The extension masquerades as "Microsoft Office Word Editor" to steal cookies, browsing history, and credentials entered into web forms.
Metrics
data_breach
2,026
September
LxBase RAT observed for the first time in attacks against Russian companies..
From July through September 2026, threat actors conducted mass phishing campaigns against Russian organizations in finance, engineering, manufacturing, energy, retail, agriculture, logistics, construction, and IT.
Metrics
data_breach
13,200
Byte
"The host is backed by a 13,200-byte PowerShell script embedded in the .rdata section that implements the Chrome Native Messaging protocol over standard input and output," Downing said.
Metrics
data_breach
524
Mb Write
"
The PowerShell script supports six file system actions -
list_drives
, to enumerate all drive letters C through Z
list_dir
, to list directory contents with file sizes
read_file
, to read arbitrary files in 512 KB chunks and those up to 524 MB
write
, to write arbitrary data to any file path
download
, to download files from the system
run
, to execute arbitrary programs
Wha…
Intelligence Sources
The Hacker News
2026-09-26
AlienVault OTX
2026-09-26
AlienVault OTX
2026-09-30
AlienVault OTX
2026-10-06
The Hacker News
2026-10-07
Ransomware Live
2026-10-08
🏴☠️ Nightspire has just published a new victim : Lumabuilt
Ransomware Live
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-08T05:45
Comprehensive Tactical Telemetry
Highly Correlated Entities
44x
organisation
Identified Entity
Nightspire
entity
8x
industry
Targeted Sector
Cryptocurrency
sector
7x
target region
Target Country
Ukraine
country
6x
tactic
MITRE ATT&CK Technique
T1588.001 - Malware
technique
4x
source region
Origin Country
Ukraine
country
4x
timeline
Temporal Reference
Oct 07, 2026
date
3x
tactic
Cyber Operation Type
Phishing
tactic
2x
general metric
Oct
7
oct
2x
infrastructure
Affected Product
Windows
software
2x
general metric
Variant
3
variant
Contextual Telemetry
Context Block
13 METRICS
attribution
Attributing Entity
CERT-UA
authority
general metric
Compromised Websites
100
compromised websites
general metric
Mode
2
mode
general metric
Hours
12
hours
general metric
Modes
0
modes
vulnerability
Exploited CVE
CVE-2023-20598
cve
general metric
Panels
28
panels
general metric
Countries
13
countries
source region
Origin Region
CIS
region
data breach
September
2,026
september
data breach
Byte
13,200
byte
general metric
Kb Chunks
512
kb chunks
data breach
Mb Write
524
mb write
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.