Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-27 · updated: 2026-09-27 · tags: [incident, financial-services] · confidence: high · severity: medium · affected_sectors: [financial-services] · au_impact: true

Ontinue's technical analysis links the "Psychedelic Stealer" previously documented by Arctic Wolf Labs in compromised Ukrainian websites to a broader malware-as-a-service platform called Lunex, building a four-stage chain aimed at Ukrainian-speaking users. A fake CAPTCHA page — a ClickFix-style Cloudflare verification lure on compromised small-business sites — leads to bogus MSI installers, which deliver LunexLoader: the loader bypasses Windows User Account Control through the CMSTPLUA COM object, then performs a bring-your-own-vulnerable-driver attack using PDFWKRNL.sys, a legitimately signed AMD Radeon kernel driver exposed to CVE-2023-20598, reverting privileges and blinding security processes while leaving them running. Ontinue notes that BYOVD is rare as a precursor to a final-stage information stealer, and its testing found neither HVCI nor the current Microsoft Vulnerable Driver Blocklist prevents this variant from loading, despite the driver hash sitting in the LOLDrivers project since March 2026. The stealer harvests credentials and data from seven Chromium-based browsers, crypto wallets and — via a 13,200-byte PowerShell native messaging host embedded in the binary's .rdata section — persistent remote filesystem access inside Chrome's own process context, surviving stealer deletion, reboots and browser restarts, alongside an injected extension granted cookies, history, tabs, proxy and scripting permissions. The operator appears Russian-speaking; the panel count has grown from six in June to 28 across 13 countries.

Attribute Detail
Sector Financial Services
Date 2026-09-27
Source The Hacker News
Reliability Tier 2
CVEs CVE-2023-20598