thehackernews.com 7 Oct 2026, 06:57 UTC

100 Compromised Websites Used Fake Cloudflare Checks to Spread LunexStealer

CyberSIXT Evidence Panel
Threat Actor
UAC-0277

CERT-UA has linked over 100 compromised websites to a campaign delivering LunexStealer, an information-stealing malware also known as Psychedelic Stealer. The sites display a forged Cloudflare verification page that purportedly confirms the visitor is human; users are then prompted to run a command which downloads and installs a malicious MSI package from a remote server (the ClickFix technique).

The operation leverages EtherHiding to determine the resource domain and script mode from a smart contract on the Polygon or Ethereum networks. The threat cluster behind the activity is named UAC-0277, and CERT-UA did not disclose the campaign’s victims or whether any systems were breached.

LunexStealer has at least three MSI variants. Variant 1 installs LunexStealer on the host; Variant 2 attempts to bypass Windows UAC, configures Defender exclusions, and uses the legitimate but vulnerable AMD driver PDFWKRNL[.]sys to blind security tools before loading LunexStealer from a remote server; Variant 3 uses DLL sideloading via FnHotkeyUtility[.]exe to load spkvol[.]dll, which decrypts and executes the stealer.

The malware also installs a browser extension, LUNARAXE, masquerading as “Microsoft Office Word Editor” to harvest cookies, history and credentials, and to enable remote browser control and arbitrary JavaScript. An auxiliary component, NAIVEMESS, retrieves Windows drives and file access via a PowerShell Native Messaging Host, with data sent to the C2 in Base64-encoded chunks.

CERT-UA suggests restricting Run dialog usage, limiting MSI installs, monitoring for msiexec[.]exe, blocking vulnerable drivers, and allowlisting extensions; Microsoft’s ASR rule to block abuse of exploited signed drivers is also recommended.

View full article

Article by CyberSIXT