Psychedelic Stealer / LunexStealer MaaS infostealer deployment
Malware Activity
Summary
Hide ▲
Show ▼
Psychedelic Stealer / LunexStealer is being deployed through the Lunex MaaS platform to steal Chromium browser credentials and cryptocurrency wallet data while keeping persistent remote access on victim systems. The malware chain uses ClickFix-style lures, bogus MSI installers, and a PowerShell-based Native Messaging Host to survive cleanup and continue operating. It also abuses PDFWKRNL.sys tied to CVE-2023-20598 to weaken defenses and bypass UAC on Windows endpoints.
Related Happenings
ChainScript RAT delivered via ClickFix-like lures
Malware Activity
H score23
First: 21.09.2026 11:39
Last: 21.09.2026 11:39
Sources 1
About this happening:
The ChainScript RAT is being delivered through ClickFix-like lures, giving operators remote access and payload deployment control on compromised Windows system...
ChainScript RAT delivered via ClickFix-like lures
Malware ActivityAbout this happening: The ChainScript RAT is being delivered through ClickFix-like lures, giving operators remote access and payload deployment control on compromised Windows system...
Fake Xeno Executor Java RAT and infostealer malware
Malware Activity
H score30
First: 03.08.2026 22:25
Last: 03.08.2026 22:25
Sources 1
About this happening:
Fake Xeno Executor installers are infecting Roblox players through gaming forums, Discord communities, and compromised or impersonated accounts, with victims runni...
Fake Xeno Executor Java RAT and infostealer malware
Malware ActivityAbout this happening: Fake Xeno Executor installers are infecting Roblox players through gaming forums, Discord communities, and compromised or impersonated accounts, with victims runni...
ACR Stealer enterprise infostealer surge
Malware Activity
H score29
First: 18.07.2026 17:17
Last: 18.07.2026 17:17
Sources 1
About this happening:
ACR Stealer attacks surged against enterprise customers, putting browser-stored passwords, authentication tokens, cookies, and sensitive documents at risk....
ACR Stealer enterprise infostealer surge
Malware ActivityAbout this happening: ACR Stealer attacks surged against enterprise customers, putting browser-stored passwords, authentication tokens, cookies, and sensitive documents at risk....
ACR Stealer browser credential and document theft activity
Malware Activity
H score29
First: 17.07.2026 11:56
Last: 17.07.2026 11:56
Sources 1
About this happening:
ACR Stealer activity has expanded across enterprise environments, with Microsoft linking the malware to late April to mid-June 2026 campaigns that use ClickFix lur...
ACR Stealer browser credential and document theft activity
Malware ActivityAbout this happening: ACR Stealer activity has expanded across enterprise environments, with Microsoft linking the malware to late April to mid-June 2026 campaigns that use ClickFix lur...
ClickFix-based TELEPUZ distribution campaign
Campaign
H score35
First: 16.07.2026 15:50
Last: 16.07.2026 15:50
Sources 1
About this happening:
The ClickFix-based TELEPUZ distribution campaign is pushing TELEPUZ through websites infected with lures, increasing the chance that victims run malicious commands and...
ClickFix-based TELEPUZ distribution campaign
CampaignAbout this happening: The ClickFix-based TELEPUZ distribution campaign is pushing TELEPUZ through websites infected with lures, increasing the chance that victims run malicious commands and...
Timeline
-
26.09.2026 21:22 2 articles · 3h ago
Psychedelic Stealer / LunexStealer MaaS infostealer deployment
Initial DisclosureThe opening stage uses compromised Ukrainian websites and ClickFix-style verification pages to lure Ukrainian-speaking users into running a bogus MSI installer. That installer delivers LunexLoader, which prepares the system for the final stealer payload.
Show sources
- Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials — thehackernews.com — 26.09.2026 21:22
- Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials — thehackernews.com — 26.09.2026 21:22