The Psychedelic Stealer, a component of the Lunex malware‑as‑a‑service (MaaS) platform, has been identified as targeting Ukrainian‑speaking users through a sophisticated four‑stage attack chain. According to security firm Ontinue, the chain begins with a fake CAPTCHA page that lures victims into a compromised Ukrainian website.
Once the user interacts with the counterfeit verification screen, the malware is delivered via a ClickFix‑style Cloudflare check. This technique mimics legitimate traffic verification, allowing the attacker to bypass basic security filters and embed the Psychedelic Stealer into the victim’s system.
After installation, the stealer exploits an AMD driver vulnerability to disable security monitoring tools. This allows it to operate undetected while harvesting browser credentials and other sensitive information from the infected machine.
Ontinue’s analysis highlights that the attack is specifically engineered for Ukrainian‑speaking users, suggesting a targeted campaign rather than a broad, indiscriminate distribution. The use of a cloud‑based verification bypass and driver exploitation points to a well‑resourced threat actor behind the Lunex MaaS network.
Security experts advise users to verify the authenticity of CAPTCHA pages and to keep their operating systems and drivers up to date. Vigilance against phishing sites and the use of reputable security software remain critical defenses against this evolving threat.
<small>Source: The Hacker News — read the original story there.</small>