
LunexStealer targets Windows visitors with fake checks
LunexStealer attackers injected more than 100 websites with fake verification checks that trick Windows visitors into installing information-stealing malware.
LunexStealer is being delivered through fake Cloudflare verification pages on more than 100 compromised websites, according to the Computer Emergency Response Team of Ukraine (CERT-UA). The agency observed the activity in September 2026 and assigned it to an attacker cluster it tracks as UAC-0277. It did not identify the campaign's victims or confirm whether visitors' computers were successfully infected. The reported website compromises and the unconfirmed outcome for visitors are distinct parts of the incident.
The affected sites contained injected JavaScript, code that runs inside a visitor's browser. Instead of presenting a genuine human-verification check, the malicious code displayed a page impersonating Cloudflare and asked visitors to run a command on their computer. CERT-UA says following that instruction downloaded and installed a malicious MSI package, a Windows software installer, from a remote server. This deception is known as ClickFix: the attacker persuades the person using the computer to perform the action that starts the infection. The report describes abuse of Cloudflare's identity, not a compromise of Cloudflare itself.
The injected code also used EtherHiding, a technique that places information needed by an attack on a blockchain rather than relying solely on a conventional web server. Here, a smart contract, a program stored on the Polygon or Ethereum network, supplied both the domain name hosting the fake verification page and the script's operating mode. CERT-UA identified three settings: mode 0 left the script inactive; mode 1 collected visitor information, including details about the website and the page the visitor came from; and mode 2 displayed the fraudulent check.
Even in mode 2, the trap was selective. CERT-UA says the fake page appeared only to Windows users arriving from search engine results, and no more than twice within 12 hours. For website owners, that matters because a visit made directly to a site's address would not meet the reported conditions for showing the lure. A page that looks normal on one visit is therefore not evidence that this particular injected code is absent. The source does not explain how the attackers initially gained access to the websites or identify their content-management software.
CERT-UA described at least three MSI variants carrying LunexStealer, also called Psychedelic Stealer. The first installs the malware directly. The second attempts to bypass Windows User Account Control (UAC), the permission checks used for changes requiring elevated access. It adds Microsoft Defender exclusions, settings that leave selected items outside antivirus scanning, and abuses the legitimate but vulnerable AMD driver PDFWKRNL.sys to interfere with security software. A driver is software that gives the operating system access to hardware functions. This variant then downloads and runs the stealer from a remote server.
The third installer uses DLL sideloading, in which a legitimate application is made to load an attacker's software library. In this case, the genuine FnHotkeyUtility.exe program loads a malicious dynamic-link library (DLL) named spkvol.dll. That library decrypts and executes LunexStealer. These are separate installation routes described by the agency, rather than evidence that every visitor encountered the same sequence.
Research documented by Arctic Wolf Labs and Ontinue also shows that LunexStealer can install LUNARAXE, a malicious browser extension posing as Microsoft Office Word Editor. Browser extensions add functions to a browser; this one steals cookies, browsing history and credentials typed into web forms. Cookies are small pieces of website data that can include information used to maintain a signed-in session. LUNARAXE also lets its operator control the browser remotely and run arbitrary JavaScript on pages.
The extension contains three modules with different responsibilities. LUNARAXE.CORE communicates with the command-and-control (C2) server, the attacker's system for issuing instructions and receiving stolen data. It processes commands and sends out cookies, browsing history, bookmarks, installed-extension details and intercepted credentials. It can manage tabs, switch extensions on or off, show notifications, execute page scripts and display deceptive overlays. LUNARAXE.STEALER captures credentials entered into forms and passes them, together with the page address, to LUNARAXE.CORE.
LUNARAXE.STRIP removes Content Security Policy (CSP) headers from HTTP responses, the messages through which websites deliver pages to browsers. CSP tells a browser which content and scripts a page is permitted to load; stripping those instructions helps the malicious extension run code without those restrictions. For website operators, the distinction is important: the reported mechanism tampers with protections in the visitor's browser, rather than demonstrating that the website never supplied them.
LunexStealer can also deploy NAIVEMESS when instructed by configuration received from its C2 server. This auxiliary component gives LUNARAXE access to Windows files through a PowerShell-based Native Messaging Host, a bridge between the browser extension and software running on the computer. CERT-UA says its commands arrive through the extension. NAIVEMESS can list drives, browse folders, read, create, overwrite and execute files. Transfers use chunks encoded in Base64, a way of representing binary data as text, while folders and file groups are first packed into ZIP archives. With NAIVEMESS installed, LUNARAXE.CORE can copy files from the computer, write files to it and run them.
CERT-UA recommends that organizations use centrally managed group policies to prevent regular users from opening the Windows Run dialog, restrict MSI installation by users without administrator rights and monitor execution of msiexec.exe, the Windows installer process. It also recommends enabling Microsoft's vulnerable driver blocklist and allowing only approved browser extensions. Microsoft separately recommends the Attack Surface Reduction (ASR) rule named "Block abuse of exploited vulnerable signed drivers", which blocks applications from writing such drivers to disk.
For businesses reviewing their endpoint and infrastructure safeguards, AEU-I offers security-first IT, infrastructure and consulting services relevant to that work, without implying involvement in this campaign. The immediate warning for visitors is straightforward: a website asking you to run a computer command to prove you are human is not a verification step to follow.
How to Protect Yourself
- Close any verification page that asks you to open the Windows Run box or paste a command into your computer.
- Do not download or open a Windows installer offered as part of a website's human-verification check.
- Open your browser's extensions menu and remove unfamiliar additions, especially an unexpected extension named Microsoft Office Word Editor.
- If you already ran a command from one of these pages, stop using that computer for sign-ins and contact your IT team or a trusted computer-support provider.
Terms Explained
- ClickFix A trick that asks you to run a harmful command while pretending it is needed to fix a problem or pass a check.
- MSI A file format used to install software on Windows computers.
- EtherHiding A technique that hides information used by an attack in records stored on a blockchain.
- DLL sideloading A method of making a trusted program load an attacker's code from a separate file.
- command-and-control (C2) server A computer attackers use to send instructions to malicious software and receive information from it.
- Content Security Policy (CSP) Website instructions that tell a browser which scripts and other content it is allowed to load.
- Native Messaging Host Software that lets a browser extension exchange information with programs outside the browser.