CERT-UA reports that attackers compromised over 100 websites by injecting malicious JavaScript that presents a fake Cloudflare bot-check. When a visitor runs the suggested command on the fake page, the browser downloads and installs an MSI package from an attacker-controlled server via a ClickFix-style lure.
The operators control the campaign through a smart contract on the Polygon or Ethereum blockchain, allowing them to change the target domain or switch the attack on and off without touching the compromised sites. The script supports three modes: off, silent visitor tracking, and a full fake verification page, and is designed to trigger only for Windows users arriving via search engines, appearing no more than twice in 12 hours for the same visitor to avoid detection.
CERT-UA analysed three MSI payload variants used in the campaign and attributes LunexStealer as the final payload. The first variant directly installs the stealer; the second attempts to bypass Windows User Account Control, adds Defender-exceptions, and deploys a vulnerable AMD driver to exploit CVE-2023-20598 (BYOVD) to disable security tooling before delivering the payload; the third variant uses DLL side-loading to drop the malicious library and decrypt and launch the stealer.
LunexStealer is a multi-purpose tool capable of remote execution, downloading and running executables, MSI packages, PowerShell scripts, and commands. It can also install a browser extension named LUNARAXE, masquerading as “Microsoft Office Word Editor,” which steals cookies, browsing history and credentials, and can remotely control the browser. A NAIVEMESS PowerShell component provides file-system access, registering as a browser-to-system messaging host.
CERT-UA recommends never entering commands on a site posing as a security check and advises restricting MSI installations and vulnerable drivers at the policy level.