LunexStealer: How Fake Cloudflare Pages on 100+ Hacked Sites Are Targeting Windows Users
Ukraine's CERT-UA tracked a September 2026 campaign in which hijacked websites served convincing but bogus human-verification prompts — tricking users into running a PowerShell command that installed an AMD-driver-abusing infostealer capable of blinding endpoint security tools entirely.
There is something grimly efficient about the setup. You visit a Ukrainian small business website — a bookseller, a hair clinic, a car parts retailer — through a search engine. Before the page loads properly, a popup appears telling you that Cloudflare needs to verify you're human. A command appears in a box. You paste it into the Windows Run dialog and press Enter. Done: you've just installed an infostealer that can empty your browser credentials, drain your cryptocurrency wallets, and leave a persistent browser backdoor that survives even if someone cleans the stealer binary off your hard drive.
That's the short version of what Ukraine's Computer Emergency Response Team (CERT-UA) documented in September 2026. The agency identified more than 100 compromised websites injected with malicious JavaScript, all funneling visitors through a fake Cloudflare "I am not a robot" check to deliver malware called LunexStealer — also known as Psychedelic Stealer. CERT-UA attributed the activity to a cluster it tracks as UAC-0277 [1].
Notably, CERT-UA did not confirm how many systems were actually compromised, or identify specific victims. The scale of infections is unknown from public reporting.
The ClickFix Trick — Why It Works
ClickFix isn't new. Security researchers have tracked this social engineering technique throughout 2026 as it's evolved from opportunistic phishing into something more deliberate. The premise is straightforward: users recognize Cloudflare's CAPTCHA-style pages as routine. Attackers replicate the look well enough that a visitor arriving from a search result — with no reason to distrust the site they clicked — may not question a prompt to "verify" themselves [2].
What makes the UAC-0277 variant interesting is that the injected JavaScript doesn't show the fake page to everyone. CERT-UA found three operating modes built into the script [1]:
- Mode 0 — inactive; the page loads normally.
- Mode 1 — passive reconnaissance, collecting data about the visitor and their referrer.
- Mode 2 — the fake Cloudflare check activates, but only for Windows users arriving from a search engine, and no more than twice per visitor within 12 hours.
That 12-hour limit is deliberate filtering. It helps avoid tripping repeated alerts on the same machine while the campaign runs quietly across a large number of sites.
Infrastructure Designed to Outlast Takedowns
Rather than hardcoding a domain for the fake verification page, the attackers used a technique called EtherHiding — storing the phishing domain and script mode in a smart contract on the Polygon or Ethereum blockchain. The injected JavaScript fetches that contract to find out which domain to load and whether to activate the ClickFix prompt [3].
The practical consequence: the attacker can rotate their infrastructure by updating one smart contract, without ever needing to touch the 100+ compromised sites again. Traditional domain-takedown responses become harder when the configuration lives on a decentralized blockchain rather than a registrar record.
Three Ways In: The MSI Variants
When a visitor triggers Mode 2 and runs the copied command, their machine calls out to a remote server and downloads an MSI installer. CERT-UA documented three distinct variants [1]:
| Variant | Delivery Method | Notable Technique |
|---|---|---|
| Variant 1 | Direct MSI install | LunexStealer dropped and executed immediately |
| Variant 2 | Loader fetches payload from C2 | UAC bypass (CMSTPLUA COM object); configures Defender exclusions; loads vulnerable AMD driver PDFWKRNL.sys via BYOVD (CVE-2023-20598) to blind EDR; fetches and runs stealer remotely |
| Variant 3 | DLL sideloading | Legitimate FnHotkeyUtility.exe loads malicious spkvol.dll, which decrypts and executes the stealer |
Variant 2 drew the most researcher attention, and the reason is worth understanding.
Blinding the Defender: BYOVD and the AMD Driver
Bring Your Own Vulnerable Driver (BYOVD) attacks work by loading a legitimate but flawed kernel-mode driver, then exploiting its kernel access to do things user-space malware cannot. It's most associated with sophisticated, well-resourced threat actors. Deploying it as the delivery mechanism for an infostealer — a commodity credential thief — is unusual enough to notice.
Lunex loads PDFWKRNL.sys, an AMD Radeon Software driver vulnerable to CVE-2023-20598, a privilege escalation flaw. The driver is used to zero out kernel callbacks — the hooks that EDR products rely on to receive notifications about process creation, thread activity, registry operations, and image loading. This doesn't kill security tools. It leaves them running normally while cutting off the event stream they depend on. From the EDR's perspective, nothing unusual is happening [4].
Ontinue researcher Rhys Downing, who published a technical teardown on September 24, 2026, noted something uncomfortable for defenders: validated testing showed neither Hypervisor-Protected Code Integrity (HVCI) nor Microsoft's current Vulnerable Driver Blocklist prevented this specific variant of PDFWKRNL.sys from loading — despite the driver hash having been catalogued in the LOLDrivers project since March 2026. That gap persists as of the time of writing [5].
What LunexStealer Actually Takes
Once running, LunexStealer communicates with a C2 panel over HTTP. It targets seven Chromium-based browsers: Chrome, Edge, Brave, Yandex Browser, Opera, Opera GX, and Vivaldi, pulling saved credentials, session cookies, and browsing history from each [4].
Cryptocurrency wallets are targeted separately — both desktop applications (Bitcoin Core, Litecoin, Exodus, Atomic Wallet, Electrum) and browser extension wallets including MetaMask, OKX Wallet, and SafePal. Session cookies and authentication tokens are sent to a dedicated C2 endpoint, distinct from the password exfiltration path, which suggests the platform was designed to handle session hijacking as a workflow in its own right.
Persistence is stacked in several layers. The stealer sets a Registry Run key, creates a hidden scheduled task named psychedelicloveUtils, and installs a Chrome Native Messaging Host — a PowerShell script embedded in the stealer's data section that runs within Chrome's own process context. Ontinue confirmed this component survives stealer binary deletion, system reboots, and browser restarts. Cleaning the main malware file does not remove it.
LUNARAXE: The Browser Extension That Stays Behind
LUNARAXE, the malicious browser extension deployed by LunexStealer, disguises itself as "Microsoft Office Word Editor" — a name that blends into a list of installed extensions without attracting immediate attention. Its declared permissions cover cookies, history, bookmarks, tabs, storage, proxy access, scripting rights, declarativeNetRequest, and all HTTP and HTTPS URLs: essentially full browser visibility and control [3].
Three internal modules power it. LUNARAXE.CORE handles C2 communication, receives commands, exfiltrates browser data, manages tabs, runs arbitrary JavaScript on web pages, and can display overlay popups. LUNARAXE.STEALER captures credentials as they're typed into forms, sending them along with the page URL to CORE. LUNARAXE.STRIP disables Content Security Policy protections by stripping CSP headers from HTTP responses — removing a defense that would otherwise block the arbitrary script execution the extension is designed to perform.
A supporting component called NAIVEMESS acts as a native-messaging host, giving the extension reach into the Windows file system through PowerShell. With NAIVEMESS in place, LUNARAXE.CORE can enumerate drives, browse directories, read and write files up to 524 MB, and execute arbitrary programs — all through the browser, all exfiltrated to the C2 server.
A MaaS Platform Expanding Quickly
LunexStealer and Psychedelic Stealer refer to the same component of a larger malware-as-a-service platform called Lunex. "Psychedelic" is the name of the executable that runs on victims' devices; Lunex is the underlying platform sold to multiple criminal groups. BlueTeamCoolTeam researcher Luke Wilkinson first identified six active Lunex C2 panels in June 2026 [4].
By the time Ontinue published its analysis in late September, that had grown to 28 unique panels across 13 countries. Panels were hosted in Russia, the US, the UK, the Netherlands, France, Germany, Turkey, and Bangladesh, among others. One panel hosted in Turkey resolved to five phishing domains impersonating brands including Sam's Club and WhatsApp Business, indicating the platform's feature set extends beyond credential theft to include active phishing operations. Panel code analysis pointed to a Russian-speaking developer or development team — an assessment based on language and code patterns, not definitive identification.
What Defenders Should Do
CERT-UA's advisory included several concrete recommendations [1]. For organizations running Windows systems:
- Prohibit standard users from accessing the Windows Run dialog via group policy. This cuts the ClickFix attack vector at the source — if the command can't be run, the chain never starts.
- Restrict MSI package installation to users with administrator rights.
- Monitor for
msiexec.exeexecutions, particularly with remote URLs in the arguments. - Enable Microsoft's vulnerable driver blocklist — noting that Ontinue's testing found this did not block the specific PDFWKRNL.sys variant used here. Treat it as one layer, not a complete control.
- Restrict browser extension installation to an organizational allowlist. This directly addresses LUNARAXE and the persistence it provides.
Microsoft separately recommends enabling the Attack Surface Reduction rule "Block abuse of exploited vulnerable signed drivers" to prevent applications from writing vulnerable signed drivers to disk [3].
The extension allowlisting point is worth emphasizing. Even if LunexStealer is detected and removed from a machine, LUNARAXE and NAIVEMESS can persist independently through the browser. Without extension controls in place, cleanup may be incomplete — and the attacker retains access through a component that many organizations aren't actively monitoring.
What Remains Unknown
CERT-UA confirmed the campaign was observed and identified the infrastructure, but did not state whether any systems were confirmed compromised or identify specific victims. The actual scale of infections is not established in public reporting. Attribution to UAC-0277 is CERT-UA's assessment; the cluster's relationship to any named group or state sponsor has not been publicly established in the sources reviewed here.
Which MSI variant gets deployed to any given victim may depend on operator configuration within the Lunex platform — meaning the severity of a specific infection can vary considerably, from a straightforward credential theft to a fully persistent browser implant with filesystem access.
The Bigger Picture on ClickFix
What makes this campaign worth watching beyond its Ukrainian targeting context is how mature ClickFix social engineering has become as a delivery mechanism. The UAC-0277 operation sits at the more sophisticated end: EtherHiding for resilient infrastructure, targeted filtering to avoid detection, BYOVD to neutralize endpoint security, and a layered persistence stack that can outlive cleanup efforts. It's not one clever trick — it's several working together.
The fundamental vulnerability here is user behavior, not a software flaw. Cloudflare verification pages appear on legitimate sites constantly, and that familiarity is exactly what the attack exploits. The defenses that matter most — blocking the Run dialog for standard users, restricting MSI installs, allowlisting extensions — are all policy controls rather than detection controls. They prevent the attack before any security tool needs to respond.
Sources & References
- CERT-UA Advisory #6319983 — UAC-0277 ClickFix on compromised websites distributing LUNEXSTEALER (September 2026)
- The Record — ClickFix campaign in Ukraine compromises over 100 websites to spread Lunex malware (Daryna Antoniuk, October 6, 2026)
- The Hacker News — 100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer (October 7, 2026)
- The Hacker News — Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials (September 26, 2026)
- Ontinue — Lunex Unmasked: A New Information Stealer Deployed Through BYOVD (Rhys Downing, September 24, 2026)

Technical Discussion & Feedback
Leave a Comment (Authenticated Users)