Skip to main content
Emerging ThreatsMalware & Ransomware

CERT-UA Warns of 100+ Sites Serving LunexStealer via Fake Cloudflare Checks

Blurred office screens surround a laptop with a fake Cloudflare verification page.

"When visiting such a site, users were shown a forged Cloudflare verification page that, under the pretext of confirming the visitor is human, prompted them to execute a command," CERT‑UA said in an advisory.

What CERT‑UA observed in September 2026

The Computer Emergency Response Team of Ukraine (CERT‑UA) reported that more than 100 compromised websites were injected with malicious JavaScript to deliver an information‑stealing malware known as LunexStealer (aka Psychedelic Stealer). The activity was observed in September 2026 and attributed by CERT‑UA to a threat cluster dubbed UAC‑0277. The advisory did not disclose the identities of the compromised sites’ owners or whether any systems were successfully breached as a result of these infections.

How ClickFix and EtherHiding were used to deliver the lure

CERT‑UA says the injected script displayed a forged Cloudflare verification page that asked visitors to execute a command; executing it downloaded and installed a malicious MSI package from a remote server — a delivery pattern the advisory describes as the ClickFix technique. The campaign also used an EtherHiding technique: the script retrieved the domain name hosting the fake verification page and the script’s operating mode from a smart contract on the Polygon or Ethereum networks.

CERT‑UA detailed three operating modes controlled via the smart contract: mode 0 — inactive; mode 1 — passive tracking that gathers site and referrer data; and mode 2 — display of the fake verification page. In mode 2 the forged prompt was shown only to Windows users who arrived from search engine results and was limited to at most two displays in a 12‑hour window.

The three MSI variants discovered

  • Variant 1: installs LunexStealer directly on the system.
  • Variant 2: attempts to bypass Windows User Account Control, configures Microsoft Defender exclusions, leverages a legitimate-but‑vulnerable AMD driver ("PDFWKRNL.sys") to blind security software, and then retrieves and runs LunexStealer from a remote server.
  • Variant 3: launches LunexStealer via DLL sideloading by using the legitimate binary "FnHotkeyUtility.exe" to load a rogue DLL "spkvol.dll", which decrypts and executes the stealer.

LunexStealer, LUNARAXE and the NAIVEMESS auxiliary component

Arctic Wolf Labs and Ontinue, referenced by CERT‑UA, document that LunexStealer is designed to install a malicious browser extension named LUNARAXE. The extension impersonates "Microsoft Office Word Editor" to steal cookies, browsing history and credentials entered into web forms; it also provides remote browser control and the ability to execute arbitrary JavaScript on pages.

CERT‑UA describes an auxiliary component called NAIVEMESS that is installed according to configuration received from the malware’s command‑and‑control (C2) server. NAIVEMESS’s primary role is to give LUNARAXE access to the Windows file system through a PowerShell‑based Native Messaging Host. Its functionality includes retrieving drive lists, browsing directories, reading, creating and overwriting files, and executing files; files are transferred in Base64‑encoded chunks and directories/file groups are pre‑archived into ZIP.

NAIVEMESS does not use a separate communication channel for commands; rather, commands are received via the extension. CERT‑UA enumerated three modules inside the extension: LUNARAXE.CORE (handles C2 communication, executes commands, exfiltrates browser data, manages tabs and extensions, serves notifications, runs JavaScript, displays overlays, and can copy/write/execute files when NAIVEMESS is present), LUNARAXE.STEALER (captures credentials from form submissions and forwards them with the page URL), and LUNARAXE.STRIP (strips Content Security Policy headers from HTTP responses to enable arbitrary JavaScript execution).

CERT‑UA and Microsoft mitigation recommendations

CERT‑UA advised organizations to take several configuration and monitoring steps: prohibit regular users from using the Windows Run dialog via group policies; restrict installation of MSI packages by users without administrator rights; monitor for executions of msiexec.exe; enable blocking of vulnerable drivers via Microsoft's vulnerable driver blocklist; and limit browser‑extension installation to allowlisted extensions. Microsoft specifically recommends enabling the Attack Surface Reduction (ASR) rule "Block abuse of exploited vulnerable signed drivers" to prevent applications from writing a vulnerable signed driver to disk.

What this means for security teams, enterprises, and users

  • Security teams: will need to watch for msiexec.exe activity and indicators tied to the ClickFix pattern, consider enabling Microsoft’s vulnerable‑driver blocklist and the ASR rule against abused signed drivers, and review extension allowlisting and Defender exclusion settings.
  • Affected enterprises and procurement leaders: are the direct audience for CERT‑UA’s group‑policy and MSI‑restriction recommendations and should evaluate administrative controls that prevent non‑privileged installation of MSI packages and the use of the Run dialog.
  • End users and visitors of compromised sites: are the immediate targets of the forged Cloudflare prompts; CERT‑UA’s description makes plain that the lure is a page that requests executing a command and that Windows users arriving from search engines were selectively targeted.

CERT‑UA’s report paints a coordinated delivery chain: compromised websites serving injected JavaScript, smart contracts on public chains steering the script’s behavior, and multiple MSI deployment variants that leverage driver‑level weaknesses, UAC bypasses, and DLL sideloading. The advisory ties the activity to UAC‑0277 and notes over 100 sites were compromised, but it leaves open the scope of successful intrusions — a discrete fact CERT‑UA did not disclose.

Source: https://thehackernews.com/2026/10/100-compromised-websites-use-fake.html