GajIPS - IPS Signature Update — GS PHISHING: Lunex MaaS phishing-overlay domains
Severity: HIGH · Priority: P2 — Lunex/Psychedelic Stealer phishing overlays, investigate on hit alongside C2 traffic
These rules detect connections to credential-phishing domains associated with the Lunex malware-as-a-service platform, also known as Psychedelic Stealer. Lunex is a Russian-developed, CIS-aligned criminal platform sold to multiple criminal groups; Psychedelic Stealer is the name of the malware component deployed on victims' devices. The platform has been active since at least June 2026; Ontinue's analysis documented 28 panels across 13 countries.
The attack chain begins with a fake CAPTCHA or ClickFix lure on a compromised legitimate website, delivers a loader (LunexLoader) that bypasses Windows User Account Control, then uses a bring-your-own-vulnerable-driver (BYOVD) technique with an AMD driver to disable kernel-level security monitoring — an unusual step for an infostealer that ensures the theft runs without endpoint protection interfering. With security tools silenced, the stealer collects credentials from seven Chromium-based browsers, extracts cryptocurrency wallet contents, and installs a PowerShell-based native messaging bridge inside the victim's browser for persistent remote file access. The platform then injects phishing overlays into real brand websites the victim visits to harvest additional credentials.
A hit on these rules indicates a device on your network is either contacting one of these phishing overlay domains directly (suggesting the user followed a lure) or, more significantly, has already been compromised by the Lunex stealer and is being served phishing overlays during active browsing. A hit should therefore be immediately correlated with the companion Lunex C2 and delivery rules in this ruleset. If a device is infected, treat it as a complete credential compromise: the stealer has had access to all browser-stored passwords, cookies, session tokens, and cryptocurrency wallets. Isolate the device, rotate all relevant credentials from a known-clean device, revoke sessions, and check for the psychedelicloveUtils scheduled task and the com.lunex.explorer native messaging bridge as persistence indicators. Rebuild the machine given the depth of browser-level compromise.