LunexStealer, also known as Psychedelic Stealer, is a 64-bit Windows information stealer with persistent command-and-control and remote execution capabilities. It collects saved passwords, cookies, authentication tokens, payment-card information, autofill data, and system information, primarily targeting Chromium-based browsers. It also steals data from desktop cryptocurrency wallets and browser wallet extensions. Its browser-data decryption capabilities include bypassing Chrome App-Bound Encryption through process injection. The malware communicates over HTTP and can download and execute programs, MSI packages, PowerShell scripts, and shell commands on demand.
LunexStealer can deploy LUNARAXE, a malicious Chromium-browser extension masquerading as Microsoft Office Word Editor. The extension exfiltrates browser data and credentials submitted through web forms, supports remote browser control, captures tab screenshots, changes proxy settings, and executes JavaScript on webpages. An additional component removes Content Security Policy protections. The PowerShell-based NAIVEMESS helper bridges the extension to the Windows filesystem through browser native messaging, enabling directory enumeration, file retrieval and modification, and program execution. Persistence mechanisms include a Run entry, a hidden logon-triggered scheduled task, and native-messaging registrations. The browser-based access mechanism can survive deletion of the main stealer executable.
A September 2026 campaign tracked by CERT-UA as UAC-0277 distributed LunexStealer through more than 100 compromised websites. Injected JavaScript presented fake Cloudflare verification challenges to selected Windows visitors arriving from search engines. These ClickFix lures persuaded users to execute commands that installed malicious MSI packages. Delivery settings were retrieved from Polygon or Ethereum smart contracts using EtherHiding. Observed installation variants included direct deployment, DLL sideloading, and deployment through LunexLoader, which attempted UAC bypass and abused a vulnerable AMD driver through CVE-2023-20598 to disable security callbacks before downloading the stealer. An analyzed campaign targeted Ukrainian-speaking users.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Another used a loader that attempted to bypass Windows User Account Control, added Microsoft Defender exclusions, and exploited CVE-2023-20598 in a vulnerable AMD driver to interfere with security tools. | Hackers compromised more than 100 websites and used fake Cloudflare verification pages to spread LUNEXSTEALER, a Windows malware capable of stealing information and accepting remote commands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Hackers compromised more than 100 websites and used fake Cloudflare verification pages to spread LUNEXSTEALER, a Windows malware capable of stealing information and accepting remote commands.
This binary, which we designate LunexStealer, is a 281 KB 64-bit executable compiled with MinGW-w64 on 12 September 2026, two days before the incident.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Establish persistence using... a hidden scheduled task named 'psychedelicloveUtils.'
Establish persistence using... a hidden scheduled task named 'psychedelicloveUtils.'
91 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows malware distributed through ClickFix prompts injected into compromised websites. Victims are persuaded to execute commands that download malicious MSI installers. It steals saved browser passwords, authentication tokens, cryptocurrency wallet data, and system information; accepts remote commands; downloads additional software; and can install LUNARAXE. It communicates over HTTP and can establish persistence through a scheduled task. One delivery variant uses a loader that attempts to bypass UAC, adds Microsoft Defender exclusions, and exploits a vulnerable AMD driver to interfere with security tools.
Credential-stealing malware delivered through fake Cloudflare verification pages on over 100 compromised websites. ClickFix commands download malicious MSI packages targeting Windows visitors arriving through search engines. LunexStealer can download and execute executables, MSI packages, PowerShell scripts, and commands, and can install the LUNARAXE browser extension. One delivery variant exploits CVE-2023-20598 through a vulnerable AMD driver to impair security tools; another uses DLL side-loading. Blockchain smart contracts store configuration for the malicious website scripts.
Information-stealing malware distributed through fake Cloudflare verification pages using ClickFix to persuade Windows users to execute commands that download malicious MSI packages. EtherHiding retrieves delivery configuration from Polygon or Ethereum smart contracts. Installer variants directly install the stealer, attempt UAC bypass and security evasion using a vulnerable AMD driver, or execute it through DLL sideloading. LunexStealer also installs the LUNARAXE malicious browser extension and can deploy NAIVEMESS according to C2 configuration. The report does not identify victims or confirm successful endpoint compromise.
Information-stealing malware distributed through compromised websites displaying fake Cloudflare verification pages. ClickFix prompts induce users to execute commands that download malicious MSI packages. Delivery variants include direct installation, UAC bypass and security evasion using a vulnerable AMD driver, and DLL sideloading. LunexStealer also installs the LUNARAXE browser extension and can deploy the NAIVEMESS filesystem-access component. CERT-UA observed the campaign in September 2026 and attributed it to UAC-0277; successful endpoint compromises were not confirmed in the report.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.