The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer).
The activity, which was observed by the agency in September 2026, has been attributed to a threat cluster dubbed UAC-0277. It did not disclose who the victims of the campaign were or if any systems were successfully compromised as a result of these attacks.
“When visiting such a site, users were shown a forged Cloudflare verification page that, under the pretext of confirming the visitor is human, prompted them to execute a command,” CERT-UA said in an advisory. “Executing the command caused a malicious MSI package to be downloaded and installed from a remote server (the ClickFix technique).”
The attacks also make use of the EtherHiding technique to retrieve the domain name of the resource from which the fake verification page is loaded, as well as the script’s operating mode, from a smart contract on the Polygon or Ethereum network.
According to CERT-UA, there are three operating modes: 0 – inactive; 1 – passive tracking of visitors that includes gathering data about the website and the page from which the visitor arrived; and 2 – displaying the fake verification page.
In Mode 2, the bogus verification page is shown only to Windows users who arrive at the site from search engine results and not more than twice in 12 hours. These ClickFix lures lead to the distribution of MSI packages that deliver LunexStealer.
At least three different variants of the MSI packages have been discovered –
- Variant 1, which installs LunexStealer on the system.
- Variant 2, which attempts to bypass Windows account control (UAC), configures Microsoft Defender exclusions, leverages the legitimate-but-vulnerable AMD driver (“PDFWKRNL.sys”) to blind security software, and then retrieves and runs LunexStealer from a remote server.
- Variant 3, which launches LunexStealer via DLL sideloading by using the legitimate binary (“FnHotkeyUtility.exe”) to load a rogue DLL (“spkvol.dll”), which decrypts and executes the stealer.
As documented by both Arctic Wolf Labs and Ontinue, LunexStealer is also designed to install a malicious browser extension called LUNARAXE. The extension masquerades as “Microsoft Office Word Editor” to steal cookies, browsing history, and credentials entered into web forms. It also allows the operator to remotely control the browser and execute arbitrary JavaScript on web pages.
The stealer also deploys an auxiliary component named NAIVEMESS that’s installed based on a configuration received from the command-and-control (C2) server. Its primary responsibility is to provide LUNARAXE with access to the Windows file system through a PowerShell-based Native Messaging Host.
“NAIVEMESS functionality includes retrieving the list of drives, browsing directories, reading, creating and overwriting files, as well as executing them,” CERT-UA said. “Files are transferred in chunks encoded in Base64, and directories and file groups are pre‑archived into ZIP.”
The component does have its own communication channel with the C2 server. Rather, commands are received via the extension, which houses three other modules –
- LUNARAXE.CORE, which handles C2 communication, receives commands, executes them, and exfiltrates browser data (i.e., cookies, browsing history, bookmarks, details about installed extensions, and intercepted credentials). It can also manage tabs, enable/disable extensions, serve notifications, run JavaScript on web pages, and display bogus overlays. It can also copy files from the computer, write files to it, and execute them if NAIVEMESS is installed.
- LUNARAXE.STEALER, which captures credentials entered into web forms and sends them to LUNARAXE.CORE, along with the page URL.
- LUNARAXE.STRIP, which disables Content Security Policy (CSP) protections on web pages by stripping CSP headers from HTTP responses with an aim to run arbitrary JavaScript code.
CERT-UA is advising organizations to prohibit regular users from using the Windows Run dialog via group policies, restrict the installation of MSI packages by users without administrator rights, monitor for the execution of “msiexec.exe,” enable blocking of vulnerable drivers via Microsoft’s vulnerable driver blocklist, and limit the installation of browser extensions to allowlisted ones.
Microsoft also recommends turning on the Attack Surface Reduction (ASR) rule “Block abuse of exploited vulnerable signed drivers” to prevent an application from writing a vulnerable signed driver to disk.