← Blog · · df00tech

Lunex MaaS Platform Uses AMD Driver Abuse and Fake CAPTCHAs to Deliver Psychedelic Stealer

security-news campaign

What happened

Researchers at Ontinue reported on a malware-as-a-service (MaaS) platform called Lunex behind the "Psychedelic Stealer," distributed through compromised Ukrainian websites. According to the report, the infection chain uses ClickFix-style fake CAPTCHA/Cloudflare verification pages to trick users into executing malicious commands, and is described as a four-stage attack chain targeting Ukrainian-speaking users. The malware reportedly abuses a legitimate AMD driver to disable security monitoring on infected hosts as part of the compromise.

Why it matters

ClickFix-style fake verification pages remain an effective initial-access technique because they rely on user interaction rather than exploiting a vulnerability, making them harder to block with traditional patching-based defenses. The use of a signed/legitimate AMD driver to interfere with security tooling is notable because it can allow malware to blind EDR or antivirus products using a trusted, signed binary — a technique often called "bring your own vulnerable driver" (BYOVD) style abuse. Combined with credential theft from browsers, this campaign creates risk for any organization or individual whose staff may browse Ukrainian-language sites, and more broadly signals that Lunex is being offered as a MaaS platform, meaning multiple threat actors could adopt this toolkit.

What defenders should watch for

  • Monitor for installation or loading of unexpected/unsigned-context AMD (or other vendor) kernel drivers, especially ones not part of a standard software deployment baseline, which can indicate BYOVD-style tampering.
  • Watch for sudden termination, tampering, or gaps in EDR/AV telemetry immediately following a driver load event — this is a common signature of security-monitoring-disable techniques.
  • Hunt for user-executed "verification" or CAPTCHA-prompt flows that lead to clipboard-paste-and-run commands (a hallmark of ClickFix-style social engineering), particularly via PowerShell or Run-dialog execution shortly after visiting an external site.
  • Review browser credential store access patterns and unusual local browser data exfiltration, consistent with stealer behavior.
  • Apply application/driver allow-listing and restrict which signed drivers are permitted to load where feasible, and ensure EDR tamper-protection features are enabled.

Developing intel

This item is based on a single vendor report (Ontinue) published Sept 26, 2026, and details are still emerging — attribution, full technical indicators, and scope of the MaaS platform's other campaigns are not yet fully public. We will track this story for updates. Read the original report at The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.