CERT-UA tracks LunexStealer delivery through fake Cloudflare checks

Ukraine’s Computer Emergency Response Team, CERT-UA, has identified more than 100 compromised websites injected with malicious JavaScript that delivers the information stealer LunexStealer, also known as Psychedelic Stealer. The activity was observed in September 2026 and attributed to a threat cluster tracked as UAC-0277.
Visitors to the affected sites are presented with a forged Cloudflare verification page. Under the guise of proving that the visitor is human, the page instructs them to execute a command. That ClickFix step downloads and installs a malicious MSI package from a remote server.
Smart contracts control the delivery logic
The campaign uses EtherHiding to retrieve the domain hosting the fake verification page and the script’s operating mode from a smart contract on either the Polygon or Ethereum network. CERT-UA described three modes: 0 for inactive operation, 1 for passive visitor tracking, and 2 for displaying the fake verification page.
In passive mode, the script gathers data about the website and the page from which a visitor arrived. In the active mode, the deceptive page is limited to Windows users who reach the compromised site from search-engine results. It is also configured to appear no more than twice within 12 hours.
Three MSI paths to the stealer
CERT-UA identified at least three malicious MSI variants. The first installs LunexStealer directly. The second attempts to bypass Windows User Account Control, configures Microsoft Defender exclusions, and uses the legitimate but vulnerable AMD driver PDFWKRNL.sys to blind security software before downloading and launching the stealer from a remote server.
The third variant uses DLL sideloading. It launches the legitimate FnHotkeyUtility.exe binary to load a rogue DLL named spkvol.dll, which decrypts and executes LunexStealer.
Browser extension expands access
Research from Arctic Wolf Labs and Ontinue has documented LunexStealer’s ability to install a malicious browser extension called LUNARAXE. Posing as “Microsoft Office Word Editor,” the extension can collect cookies, browsing history, and credentials entered into web forms. It can also let an operator control the browser remotely and run arbitrary JavaScript on pages.
An auxiliary component named NAIVEMESS may be installed in response to configuration from the command-and-control server. It gives LUNARAXE access to the Windows file system through a PowerShell-based Native Messaging Host. CERT-UA said its functions include listing drives, browsing directories, reading, creating, overwriting, and executing files; files may be transferred in Base64-encoded chunks, while directories and file groups are archived into ZIP files.
LUNARAXE includes modules for command-and-control communication, browser-data exfiltration, web-form credential capture, and removal of Content Security Policy headers from HTTP responses. Its capabilities include managing tabs, enabling or disabling extensions, showing notifications and overlays, and running JavaScript on webpages.
Controls for Windows and browser exposure
CERT-UA recommends using Group Policy to prevent regular users from opening the Windows Run dialog, restricting MSI installation for users without administrator rights, and monitoring execution of msiexec.exe. Organizations should also enable Microsoft’s vulnerable driver blocklist, limit browser extensions to allowlisted software, and consider the Attack Surface Reduction rule that blocks abuse of exploited vulnerable signed drivers. In practical terms, businesses should treat unexpected verification prompts that require a local command as a security event and combine user restrictions with monitoring of MSI, driver, and browser-extension activity.

