As reported by The Hacker News, the Lunex malware-as-a-service platform — also tracked as Psychedelic Stealer — has been observed using a Bring Your Own Vulnerable Driver (BYOVD) technique to neutralize endpoint security before deploying its credential-stealing payload. This represents a notable escalation in the info-stealer ecosystem that defenders should not dismiss as a regional concern.

Threat Alert: As reported by The Hacker News, the Lunex malware-as-a-service platform — also tracked as Psychedelic Stealer — has been observed using a Bring Your Own Vulnerable Driver (BYOVD) technique to neutralize endpoint security before deploying its credential-stealing payload.

Why This Matters: The BYOVD Threshold Crossing

BYOVD attacks — where threat actors load a legitimately signed but vulnerable kernel driver to gain ring-0 access — have historically been the province of ransomware affiliates and nation-state operators. Seeing this technique embedded in a commodity MaaS stealer platform signals that kernel-level defense evasion is now productized and available to lower-tier criminal operators. The barrier to entry for blinding EDR has effectively dropped.

What makes Lunex particularly insidious is its approach to security tooling: rather than killing security processes outright — which would trigger alerts and generate forensic artifacts — the malware blinds them while keeping them running. A defender looking at their EDR console sees healthy agent status. The telemetry feed simply goes dark. This is the kind of stealth that allows dwell time to extend from minutes to days.

Vulnerability Details

FieldDetails
CVECVE-2023-20598
Affected ComponentAMD Radeon Software kernel-mode driver (PDFWKRNL.sys)
SeverityHigh — local privilege escalation to kernel
ExploitationActive exploitation observed in the wild via Lunex stealer campaign
Patch StatusAMD has released updated drivers; affected organizations should verify driver versions and apply vendor updates

The Native Messaging Host Persistence Problem

Lunex's use of a PowerShell-based Native Messaging Host installed inside the victim's browser deserves specific attention. Native Messaging Hosts are a legitimate browser extension API that allows extensions to communicate with native applications. By registering a malicious host, Lunex establishes persistence that lives inside the browser's own trusted architecture — surviving browser restarts, profile resets, and even some endpoint cleanup procedures.

This isn't just a credential grab — it's a persistent remote filesystem access channel disguised as browser functionality. The browser becomes both the target and the transport.

Traditional persistence detection often focuses on registry Run keys, scheduled tasks, and startup folders. Native Messaging Hosts registered via JSON manifest files in browser-specific directories frequently slip through these checks. Defenders need browser-specific monitoring to catch this technique.

Who Is at Risk

The Native Messaging Host Persistence Problem
Ukrainian-speaking users are the immediate target population, but the MaaS model means affiliates will expand to other geographies and languages
Organizations with AMD Radeon-equipped endpoints are at elevated risk if vulnerable driver versions remain installed
Cryptocurrency holders and exchanges — Lunex explicitly targets wallet data across multiple wallet extensions
Any environment relying on Chromium-based browsers — seven browser variants are targeted, covering the majority of enterprise and consumer browsing
Environments without driver blocklist enforcement — Windows environments without Microsoft's Vulnerable Driver Blocklist enabled are fully exposed to BYOVD

Shield53 Recommendations — Immediate Actions

1. Enable and Verify Microsoft Vulnerable Driver Blocklist

This is the single most impactful mitigation against BYOVD attacks. On Windows 10 1903+ and Windows 11, verify that the blocklist is enabled via HVCI/memory integrity settings or via Group Policy. Note that enabling HVCI may require firmware (UEFI/Secure Boot) compliance — test before broad deployment.

2. Audit and Remove Vulnerable AMD Drivers

Inventory all endpoints for PDFWKRNL.sys and other AMD kernel drivers. Remove outdated versions and deploy patched drivers from AMD's official advisory. Consider whether AMD Radeon Software is necessary on enterprise endpoints at all — if not, remove it entirely.

3. Deploy EDR Tamper Protection

Modern EDR platforms (Microsoft Defender for Endpoint, CrowdStrike, SentinelOne) offer tamper protection features that resist kernel-level interference. Ensure these are enabled and that you have alerting for tamper attempts — even failed ones indicate active adversary presence.

4. Monitor for Native Messaging Host Abuse

Establish detection rules for new Native Messaging Host registrations:

  • Monitor %APPDATA%\Mozilla\NativeMessagingHosts\ and equivalent Chrome/Edge/Brave paths
  • Alert on any new JSON manifest files appearing in these directories
  • Alert on PowerShell child processes spawned from browser processes

5. Harden Browser Security Posture

  • Enforce browser extension allowlisting via enterprise policy
  • Disable or restrict Native Messaging API via Group Policy where feasible
  • Deploy browser isolation for high-risk users handling cryptocurrency or credentials
  • Enable Enhanced Protection Mode in Chromium-based browsers

6. Train Users on ClickFix Lures

The fake CAPTCHA / Cloudflare verification pattern remains highly effective because it exploits a conditioned response — users have been trained to complete verification checks. Security awareness training must specifically address the ClickFix pattern and instruct users never to run commands copied from web pages.

Broader Implications

The Lunex campaign illustrates a trend Shield53 has been tracking: the downward diffusion of advanced techniques. What required an APT-level operator in 2022 is now available as a MaaS subscription in 2026. The BYOVD technique, UAC bypass via COM object abuse, and kernel-level security blinding were once hallmarks of sophisticated operators — they are now product features.

For defenders, this means the assumption that info stealers are "just" credential collectors is no longer valid. Modern stealer campaigns can operate at the same technical level as ransomware precursors, and should be treated with the same urgency. Detection and response playbooks for stealer infections need to include kernel-level forensic analysis, driver integrity verification, and browser persistence hunting — not just credential rotation.

The MaaS model also means the Ukrainian targeting is a starting point, not a boundary. Expect Lunex affiliates to expand to English-language lures, compromised Western websites, and additional delivery vectors beyond ClickFix. Prepare now rather than react later.