VYPR
researchPublished Oct 7, 2026· 1 source

Over 100 Websites Compromised to Distribute LunexStealer via Fake Cloudflare Checks

Threat actors are leveraging over 100 compromised websites to distribute the LunexStealer information-stealing malware by tricking users with fake Cloudflare verification pages.

A coordinated campaign attributed to threat cluster UAC-0277 has compromised more than 100 websites, injecting malicious JavaScript to deliver the LunexStealer (also known as Psychedelic Stealer) information-stealing malware. The Computer Emergency Response Team of Ukraine (CERT-UA) observed this activity in September 2026, noting that the attackers employ a sophisticated social engineering tactic to lure victims.

When users visit one of these compromised sites, they are presented with a forged Cloudflare verification page. This page falsely claims to be verifying the user's humanity, prompting them to execute a command. Upon execution, this command initiates the download and installation of a malicious MSI package from a remote server, a technique CERT-UA has dubbed 'ClickFix.' The ultimate goal is to deploy the LunexStealer malware onto the victim's system.

Further complicating detection, the attacks utilize the EtherHiding technique to dynamically retrieve configuration details from a smart contract on the Polygon or Ethereum network. This allows the attackers to control the malware's behavior, with three distinct operating modes identified: inactive, passive visitor tracking, and the active display of the fake verification page. The fake verification page is specifically targeted at Windows users arriving from search engine results, and is limited to appearing no more than twice within a 12-hour period to avoid suspicion.

CERT-UA has identified at least three variants of the MSI packages used in this campaign, each employing different methods to achieve their objective. Variant 1 directly installs LunexStealer. Variant 2 goes further by attempting to bypass Windows User Account Control (UAC), configuring Microsoft Defender exclusions, and using a legitimate but vulnerable AMD driver to blind security software before downloading and running the stealer. Variant 3 uses DLL sideloading, leveraging a legitimate executable to load a malicious DLL that decrypts and executes the stealer.

LunexStealer is also known to install a malicious browser extension called LUNARAXE, which masquerades as a "Microsoft Office Word Editor." This extension is designed to steal cookies, browsing history, and credentials entered into web forms. It also grants operators remote control over the browser and the ability to execute arbitrary JavaScript on web pages, significantly expanding the potential for data theft and further compromise.

An auxiliary component named NAIVEMESS is also deployed, providing LUNARAXE with access to the Windows file system via a PowerShell-based Native Messaging Host. NAIVEMESS can retrieve drive lists, browse directories, read, create, and overwrite files, and execute them. Files are exfiltrated in Base64 encoded chunks, with directories and file groups often pre-archived into ZIP files.

CERT-UA recommends several mitigation strategies for organizations. These include prohibiting the use of the Windows Run dialog for regular users, restricting MSI package installations for non-administrator users, monitoring for "msiexec.exe" execution, enabling Microsoft's vulnerable driver blocklist, and limiting browser extension installations to an allowlist. Microsoft also advises enabling the Attack Surface Reduction (ASR) rule "Block abuse of exploited vulnerable signed drivers."

This campaign highlights the evolving tactics of information-stealing malware distribution, combining website compromises with sophisticated social engineering and advanced evasion techniques. The use of fake verification pages and multiple malware variants demonstrates a persistent effort by threat actors to steal sensitive user data and maintain access to compromised systems.

Synthesized by Vypr AI