Illustration of a lock and a cloud icon, symbolizing compromised Cloudflare security and data theft.
Uncategorized

Fake Cloudflare Checks Unleash LunexStealer: Over 100 Websites Compromised

Share
Share
Pinterest Hidden

Cybersecurity Alert: Sophisticated Malware Campaign Targets Over 100 Websites

A significant cyber threat has emerged, with the Computer Emergency Response Team of Ukraine (CERT-UA) uncovering a widespread campaign involving over 100 compromised websites. These sites have been weaponized with malicious JavaScript to distribute a potent information-stealing malware known as LunexStealer (also referred to as Psychedelic Stealer). The campaign, observed in September 2026, has been attributed to a threat cluster identified as UAC-0277. While CERT-UA has not disclosed specific victim details or the extent of successful compromises, the sophistication of the attack warrants immediate attention from organizations and individual users alike.

The Deceptive Cloudflare Lure: A New Phishing Frontier

The attackers employ an insidious technique to ensnare victims. Upon visiting a compromised website, users are confronted with a meticulously forged Cloudflare verification page. This page, masquerading as a routine human verification check, cunningly prompts users to execute a command. CERT-UA warns that executing this command triggers the download and installation of a malicious MSI package from a remote server, a technique dubbed ‘ClickFix’.

Adding another layer of stealth, the campaign leverages the ‘EtherHiding’ technique. This method involves retrieving crucial operational data—such as the domain name of the fake verification page and the script’s operating mode—directly from a smart contract hosted on either the Polygon or Ethereum network. This decentralized approach makes detection and takedown more challenging.

Understanding LunexStealer’s Operational Modes

CERT-UA has identified three distinct operating modes for the malicious script:

  • Mode 0: Inactive – The script remains dormant.
  • Mode 1: Passive Tracking – Gathers data about the website and the visitor’s referral page without immediate malicious action.
  • Mode 2: Active Deception – Displays the fake Cloudflare verification page. This mode is selectively activated, targeting only Windows users arriving from search engine results, and is limited to appearing no more than twice within a 12-hour period to avoid suspicion.

The Multi-Variant Threat: LunexStealer’s Evolving Payload

The ClickFix lures ultimately lead to the deployment of LunexStealer via various MSI packages, showcasing the attackers’ adaptability:

  • Variant 1: Direct Installation – Installs LunexStealer directly onto the system.
  • Variant 2: Advanced Evasion – This more sophisticated variant attempts to bypass Windows User Account Control (UAC), configures exclusions within Microsoft Defender, and exploits a legitimate-but-vulnerable AMD driver (PDFWKRNL.sys) to blind security software. It then retrieves and executes LunexStealer from a remote server.
  • Variant 3: DLL Sideloading – Utilizes a legitimate binary (FnHotkeyUtility.exe) to sideload a rogue DLL (spkvol.dll). This rogue DLL then decrypts and launches the stealer, a common technique for evading detection.

Beyond the Stealer: LUNARAXE and NAIVEMESS

As detailed by cybersecurity firms Arctic Wolf Labs and Ontinue, LunexStealer is not a standalone threat. It is designed to install a malicious browser extension named LUNARAXE. This extension cleverly masquerades as “Microsoft Office Word Editor” to pilfer sensitive data, including cookies, browsing history, and credentials entered into web forms. Alarmingly, LUNARAXE also grants the attacker remote control over the browser, enabling the execution of arbitrary JavaScript on visited web pages.

Furthermore, the stealer deploys an auxiliary component called NAIVEMESS, configured based on instructions from the command-and-control (C2) server. NAIVEMESS’s primary role is to facilitate LUNARAXE’s access to the Windows file system through a PowerShell-based Native Messaging Host. CERT-UA confirms that NAIVEMESS can retrieve drive lists, browse directories, read, create, and overwrite files, and even execute them. Files are transferred in Base64-encoded chunks, with directories and file groups pre-archived into ZIP files.

Interestingly, NAIVEMESS does not communicate directly with the C2 server. Instead, commands are relayed via the LUNARAXE extension, which itself houses three critical modules:

  • LUNARAXE.CORE: Manages C2 communication, receives and executes commands, and exfiltrates browser data (cookies, history, bookmarks, extensions, intercepted credentials). It can also manage tabs, enable/disable extensions, display notifications, run JavaScript, and create bogus overlays. If NAIVEMESS is present, it can also copy, write, and execute files on the system.
  • LUNARAXE.STEALER: Specifically captures credentials from web forms and transmits them to LUNARAXE.CORE, along with the page URL.
  • LUNARAXE.STRIP: Disables Content Security Policy (CSP) protections on web pages by stripping CSP headers from HTTP responses, thereby enabling the execution of arbitrary JavaScript code.

Recommendations for Enhanced Cybersecurity

In light of this evolving threat, CERT-UA provides crucial recommendations for organizations:

  • Restrict User Permissions: Prohibit regular users from utilizing the Windows Run dialog via group policies.
  • Control MSI Installations: Restrict the installation of MSI packages by users without administrator rights.
  • Monitor Executables: Actively monitor for the execution of “msiexec.exe.”
  • Leverage Driver Blocklists: Enable the blocking of vulnerable drivers through Microsoft’s vulnerable driver blocklist.
  • Whitelist Browser Extensions: Limit the installation of browser extensions to only those explicitly allowlisted.

Microsoft further advises activating the Attack Surface Reduction (ASR) rule “Block abuse of exploited vulnerable signed drivers” to prevent applications from writing vulnerable signed drivers to disk. Staying vigilant and implementing these protective measures are paramount in safeguarding against sophisticated threats like LunexStealer.


For more details, visit our website.

Source: Link

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *