
The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer).
The activity, which was observed by the agency in September 2026, has been attributed to a threat cluster dubbed UAC-0277. It did not disclose who the victims of the campaign were or if any systems were successfully compromised as a result of these attacks.
“When visiting such a site, users were shown a forged Cloudflare verification page that, under the pretext of confirming the visitor is human, prompted them to execute a command,” CERT-UA said in an advisory. “Executing the command caused a malicious MSI package to be downloaded and installed from a remote server (the ClickFix technique).”
The attacks also make use of the EtherHiding technique to retrieve the domain name of the resource from which the fake verification page is loaded, as well as the script’s operating mode, from a smart contract on the Polygon or Ethereum network.
According to CERT-UA, there are three operating modes: 0 – inactive; 1 – passive tracking of visitors that includes gathering data about the website and the page from which the visitor arrived; and 2 – displaying the fake verification page.
In Mode 2, the bogus verification page is shown only to Windows users who arrive at the site from search engine results and not more than twice in 12 hours. These ClickFix lures lead to the distribution of MSI packages that deliver LunexStealer.
At least three different variants of the MSI packages have been discovered –
As documented by both Arctic Wolf Labs and Ontinue, LunexStealer is also designed to install a malicious browser extension called LUNARAXE. The extension masquerades as “Microsoft Office Word Editor” to steal cookies, browsing history, and credentials entered into web forms. It also allows the operator to remotely control the browser and execute arbitrary JavaScript on web pages.
The stealer also deploys an auxiliary component named NAIVEMESS that’s installed based on a configuration received from the command-and-control (C2) server. Its primary responsibility is to provide LUNARAXE with access to the Windows file system through a PowerShell-based Native Messaging Host.
“NAIVEMESS functionality includes retrieving the list of drives, browsing directories, reading, creating and overwriting files, as well as executing them,” CERT-UA said. “Files are transferred in chunks encoded in Base64, and directories and file groups are pre‑archived into ZIP.”
The component does have its own communication channel with the C2 server. Rather, commands are received via the extension, which houses three other modules –
CERT-UA is advising organizations to prohibit regular users from using the Windows Run dialog via group policies, restrict the installation of MSI packages by users without administrator rights, monitor for the execution of “msiexec.exe,” enable blocking of vulnerable drivers via Microsoft’s vulnerable driver blocklist, and limit the installation of browser extensions to allowlisted ones.
Microsoft also recommends turning on the Attack Surface Reduction (ASR) rule “Block abuse of exploited vulnerable signed drivers” to prevent an application from writing a vulnerable signed driver to disk.
#100+ #checks #cloudflare #compromised #deliver #fake #lunexstealer #news #use #websites — News
© Bulletproof Servers. All rights reserved.