Full Report
The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer). The activity, which was observed by the agency in September 2026, has been attributed to a threat cluster dubbed UAC-0277. It did not disclose who the
Analysis Summary
# Incident Report: UAC-0277 LunexStealer Campaign via "ClickFix" Lures
## Executive Summary
In September 2026, the Computer Emergency Response Team of Ukraine (CERT-UA) identified a large-scale campaign by threat cluster UAC-0277 involving over 100 compromised websites. These sites were injected with malicious JavaScript that used forged Cloudflare verification pages to trick users into executing commands that installed LunexStealer (aka Psychedelic Stealer). The malware uses advanced techniques, including vulnerable driver abuse (BYOVD) and malicious browser extensions, to exfiltrate credentials and maintain file system access.
## Incident Details
- **Discovery Date:** September 2026
- **Incident Date:** Ongoing as of September/October 2026
- **Affected Organization:** Over 100 compromised websites (Specific victims not disclosed)
- **Sector:** Cross-sector (Web users arriving from search engines)
- **Geography:** Ukraine (Primary detection by CERT-UA)
## Timeline of Events
### Initial Access
- **Date/Time:** September 2026
- **Vector:** Compromised legitimate websites injected with malicious JavaScript.
- **Details:** Attackers utilized the **"EtherHiding"** technique, leveraging smart contracts on the Polygon/Ethereum blockchains to retrieve malicious domain names and operating instructions for the script.
### Lateral Movement
- **Details:** The report focuses on endpoint compromise rather than internal lateral movement. However, the **NAIVEMESS** component allows for remote file execution and directory browsing, facilitating further movement within a compromised host or network.
### Data Exfiltration/Impact
- **Details:** The primary goal is the theft of browser cookies, history, and credentials. The **LUNARAXE** extension intercepts form data and strips Content Security Policy (CSP) headers to facilitate arbitrary JavaScript execution.
### Detection & Response
- **Discovery:** Identified by CERT-UA monitoring activity associated with UAC-0277.
- **Response:** CERT-UA issued an advisory detailing the TTPs, malware variants, and technical recommendations for mitigation.
## Attack Methodology
- **Initial Access:** **ClickFix Technique.** Users are shown a fake Cloudflare "verify you are human" page and prompted to copy-paste/run a command (typically into the Windows Run box or PowerShell).
- **Persistence:** MSI packages install the stealer; use of scheduled tasks or startup folders is implied by the nature of the "LUNARAXE" browser extension and DLL sideloading.
- **Privilege Escalation:** Use of **Variant 2** MSI, which attempts to bypass User Account Control (UAC).
- **Defense Evasion:**
- **BYOVD:** Exploiting a vulnerable AMD driver (`PDFWKRNL.sys`) to disable security software.
- **DLL Sideloading:** Using a legitimate binary (`FnHotkeyUtility.exe`) to load `spkvol.dll`.
- **Conditional Triggering:** Lures only appear to Windows users coming from search engines (max twice per 12 hours).
- **Credential Access:** **LUNARAXE.STEALER** captures credentials from web forms; **LUNARAXE.CORE** steals stored browser cookies and history.
- **Discovery:** **NAIVEMESS** component retrieves drive lists and directory structures.
- **Collection:** Files are pre-archived into ZIP format and encoded in Base64 for transfer.
- **Exfiltration:** Data is sent to the C2 via the **LUNARAXE.CORE** extension module.
- **Impact:** Complete compromise of web identity and local file system access via PowerShell-based Native Messaging Host.
## Impact Assessment
- **Financial:** Unknown; potential for high loss due to stolen banking/corporate credentials.
- **Data Breach:** High; includes cookies, browsing history, saved passwords, and arbitrary local files.
- **Operational:** High; attackers can execute arbitrary code and manage browser tabs remotely.
- **Reputational:** Significant for the 100+ compromised websites used to host the lures.
## Indicators of Compromise
*Note: Specific hashes/IPs were not fully listed in the summary text, but the following were identified:*
- **File Indicators:**
- `PDFWKRNL.sys` (Vulnerable AMD Driver)
- `FnHotkeyUtility.exe` (Legitimate binary for sideloading)
- `spkvol.dll` (Malicious DLL)
- `NAIVEMESS` (PowerShell-based component)
- **Behavioral Indicators:**
- Unusual interaction with Polygon/Ethereum smart contracts from a web browser.
- Requests to download `.msi` packages following "Cloudflare" checks.
- Installation of browser extension named "Microsoft Office Word Editor."
## Response Actions
- **Containment:** CERT-UA advised blocking the C2 domains and restricting the execution of MSI packages.
- **Eradication:** Removal of the LUNARAXE extension and associated MSI-installed files.
- **Recovery:** Restoration of compromised websites by removing the injected JavaScript.
## Lessons Learned
- **Blockchain Abuse:** Attackers are increasingly using smart contracts (EtherHiding) to host C2 infrastructure, making traditional domain blocking more difficult.
- **Social Engineering Evolution:** The "ClickFix" method bypasses automated security by tricking the user into manually executing the initial payload.
## Recommendations
- **Technical:**
- Prohibit regular users from using the Windows "Run" dialog via Group Policy.
- Restrict or monitor the installation of MSI packages.
- Implement browser extension whitelisting to prevent unauthorized extensions like "Microsoft Office Word Editor."
- **Policy:**
- User awareness training focusing on "ClickFix" lures—remind users that legitimate verification checks (like Cloudflare) never require manual command execution.
- Deploy EDR solutions capable of detecting "Bring Your Own Vulnerable Driver" (BYOVD) attacks.