Skip to content

LunexStealer: How Fake Cloudflare Pages on 100+ Hacked Sites Are Robbing Windows Users

LunexStealer: How Fake Cloudflare Pages on 100+ Hacked Sites Are Robbing Windows Users

LunexStealer: How Fake Cloudflare Pages on 100+ Hacked Sites Are Targeting Windows Users

Ukraine's CERT-UA tracked a September 2026 campaign in which hijacked websites served convincing but bogus human-verification prompts — tricking users into running a PowerShell command that installed an AMD-driver-abusing infostealer capable of blinding endpoint security tools entirely.

LunexStealer ClickFix Delivery Chain — Conceptual Diagram Four-stage flow: compromised Ukrainian website injects JavaScript that fetches operating mode from Ethereum smart contract, shows fake Cloudflare CAPTCHA to Windows search visitors, tricks user into running msiexec command, which downloads and installs LunexStealer COMPROMISED WEBSITE Small Ukrainian businesses (clinic, bookseller, etc.) Injected JS reads mode from Polygon/Ethereum smart contract Windows + search visitors only FAKE CLOUDFLARE CAPTCHA PAGE "Verify you are human" msiexec /i /q /url... Click to copy Paste into Windows Run dialog, press Enter Max 2x per visitor / 12 hrs MSI INSTALLER Variant 1: Direct install Variant 2: UAC bypass + BYOVD AMD driver + Defender exclusions Variant 3: DLL sideload via FnHotkeyUtility.exe 3 variants — CERT-UA LUNEXSTEALER Browser credentials Cookies + session tokens Crypto wallets LUNARAXE browser ext. NAIVEMESS PS host Registry + scheduled task persistence 7 Chromium browsers Conceptual diagram — UAC-0277 LunexStealer delivery chain | Source: Generated by UnpanicTech
Conceptual illustration of the UAC-0277 ClickFix delivery chain, from compromised website to LunexStealer installation. Source: Generated by UnpanicTech.

There is something grimly efficient about the setup. You visit a Ukrainian small business website — a bookseller, a hair clinic, a car parts retailer — through a search engine. Before the page loads properly, a popup appears telling you that Cloudflare needs to verify you're human. A command appears in a box. You paste it into the Windows Run dialog and press Enter. Done: you've just installed an infostealer that can empty your browser credentials, drain your cryptocurrency wallets, and leave a persistent browser backdoor that survives even if someone cleans the stealer binary off your hard drive.

That's the short version of what Ukraine's Computer Emergency Response Team (CERT-UA) documented in September 2026. The agency identified more than 100 compromised websites injected with malicious JavaScript, all funneling visitors through a fake Cloudflare "I am not a robot" check to deliver malware called LunexStealer — also known as Psychedelic Stealer. CERT-UA attributed the activity to a cluster it tracks as UAC-0277 [1].

Notably, CERT-UA did not confirm how many systems were actually compromised, or identify specific victims. The scale of infections is unknown from public reporting.

The ClickFix Trick — Why It Works

ClickFix isn't new. Security researchers have tracked this social engineering technique throughout 2026 as it's evolved from opportunistic phishing into something more deliberate. The premise is straightforward: users recognize Cloudflare's CAPTCHA-style pages as routine. Attackers replicate the look well enough that a visitor arriving from a search result — with no reason to distrust the site they clicked — may not question a prompt to "verify" themselves [2].

What makes the UAC-0277 variant interesting is that the injected JavaScript doesn't show the fake page to everyone. CERT-UA found three operating modes built into the script [1]:

  • Mode 0 — inactive; the page loads normally.
  • Mode 1 — passive reconnaissance, collecting data about the visitor and their referrer.
  • Mode 2 — the fake Cloudflare check activates, but only for Windows users arriving from a search engine, and no more than twice per visitor within 12 hours.

That 12-hour limit is deliberate filtering. It helps avoid tripping repeated alerts on the same machine while the campaign runs quietly across a large number of sites.

Infrastructure Designed to Outlast Takedowns

Rather than hardcoding a domain for the fake verification page, the attackers used a technique called EtherHiding — storing the phishing domain and script mode in a smart contract on the Polygon or Ethereum blockchain. The injected JavaScript fetches that contract to find out which domain to load and whether to activate the ClickFix prompt [3].

The practical consequence: the attacker can rotate their infrastructure by updating one smart contract, without ever needing to touch the 100+ compromised sites again. Traditional domain-takedown responses become harder when the configuration lives on a decentralized blockchain rather than a registrar record.

Three Ways In: The MSI Variants

When a visitor triggers Mode 2 and runs the copied command, their machine calls out to a remote server and downloads an MSI installer. CERT-UA documented three distinct variants [1]:

Variant Delivery Method Notable Technique
Variant 1 Direct MSI install LunexStealer dropped and executed immediately
Variant 2 Loader fetches payload from C2 UAC bypass (CMSTPLUA COM object); configures Defender exclusions; loads vulnerable AMD driver PDFWKRNL.sys via BYOVD (CVE-2023-20598) to blind EDR; fetches and runs stealer remotely
Variant 3 DLL sideloading Legitimate FnHotkeyUtility.exe loads malicious spkvol.dll, which decrypts and executes the stealer

Variant 2 drew the most researcher attention, and the reason is worth understanding.

Blinding the Defender: BYOVD and the AMD Driver

Lunex Variant 2 — BYOVD Attack Chain (Conceptual) Step-by-step chain: MSI Loader performs UAC bypass and sets Defender exclusions, then drops AMD PDFWKRNL.sys driver vulnerable to CVE-2023-20598 into kernel, zeroing EDR callbacks so security tools run blind, then LunexStealer fetches from C2 and installs LUNARAXE browser extension MSI LOADER UAC bypass via CMSTPLUA COM Defender exclusions configured Drops AMD PDFWKRNL.sys Stage 1 BYOVD CVE-2023-20598 PDFWKRNL.sys loaded into kernel Kernel callbacks ZEROED OUT EDR tools running but receiving no events Stage 2 — Ontinue: HVCI/blocklist gap LUNEXSTEALER Fetched from C2 193.178.159[.]128 7 Chromium browsers Crypto wallets Registry Run key Scheduled task psychedelicloveUtils Stage 3 LUNARAXE + NAIVEMESS Extension: "MS Office Word Editor" CORE: C2 comms, remote browser STEALER: form credential harvest STRIP: removes CSP headers NAIVEMESS: PowerShell NMH full filesystem access Persists after stealer deleted Stage 4 — persistent browser implant Conceptual diagram — Lunex Variant 2 BYOVD chain | Source: Generated by UnpanicTech
Conceptual diagram of the Lunex Variant 2 attack chain, from UAC bypass through EDR blinding to persistent browser implant. Source: Generated by UnpanicTech.

Bring Your Own Vulnerable Driver (BYOVD) attacks work by loading a legitimate but flawed kernel-mode driver, then exploiting its kernel access to do things user-space malware cannot. It's most associated with sophisticated, well-resourced threat actors. Deploying it as the delivery mechanism for an infostealer — a commodity credential thief — is unusual enough to notice.

Lunex loads PDFWKRNL.sys, an AMD Radeon Software driver vulnerable to CVE-2023-20598, a privilege escalation flaw. The driver is used to zero out kernel callbacks — the hooks that EDR products rely on to receive notifications about process creation, thread activity, registry operations, and image loading. This doesn't kill security tools. It leaves them running normally while cutting off the event stream they depend on. From the EDR's perspective, nothing unusual is happening [4].

Ontinue researcher Rhys Downing, who published a technical teardown on September 24, 2026, noted something uncomfortable for defenders: validated testing showed neither Hypervisor-Protected Code Integrity (HVCI) nor Microsoft's current Vulnerable Driver Blocklist prevented this specific variant of PDFWKRNL.sys from loading — despite the driver hash having been catalogued in the LOLDrivers project since March 2026. That gap persists as of the time of writing [5].

What LunexStealer Actually Takes

Once running, LunexStealer communicates with a C2 panel over HTTP. It targets seven Chromium-based browsers: Chrome, Edge, Brave, Yandex Browser, Opera, Opera GX, and Vivaldi, pulling saved credentials, session cookies, and browsing history from each [4].

Cryptocurrency wallets are targeted separately — both desktop applications (Bitcoin Core, Litecoin, Exodus, Atomic Wallet, Electrum) and browser extension wallets including MetaMask, OKX Wallet, and SafePal. Session cookies and authentication tokens are sent to a dedicated C2 endpoint, distinct from the password exfiltration path, which suggests the platform was designed to handle session hijacking as a workflow in its own right.

Persistence is stacked in several layers. The stealer sets a Registry Run key, creates a hidden scheduled task named psychedelicloveUtils, and installs a Chrome Native Messaging Host — a PowerShell script embedded in the stealer's data section that runs within Chrome's own process context. Ontinue confirmed this component survives stealer binary deletion, system reboots, and browser restarts. Cleaning the main malware file does not remove it.

LUNARAXE: The Browser Extension That Stays Behind

LUNARAXE, the malicious browser extension deployed by LunexStealer, disguises itself as "Microsoft Office Word Editor" — a name that blends into a list of installed extensions without attracting immediate attention. Its declared permissions cover cookies, history, bookmarks, tabs, storage, proxy access, scripting rights, declarativeNetRequest, and all HTTP and HTTPS URLs: essentially full browser visibility and control [3].

Three internal modules power it. LUNARAXE.CORE handles C2 communication, receives commands, exfiltrates browser data, manages tabs, runs arbitrary JavaScript on web pages, and can display overlay popups. LUNARAXE.STEALER captures credentials as they're typed into forms, sending them along with the page URL to CORE. LUNARAXE.STRIP disables Content Security Policy protections by stripping CSP headers from HTTP responses — removing a defense that would otherwise block the arbitrary script execution the extension is designed to perform.

A supporting component called NAIVEMESS acts as a native-messaging host, giving the extension reach into the Windows file system through PowerShell. With NAIVEMESS in place, LUNARAXE.CORE can enumerate drives, browse directories, read and write files up to 524 MB, and execute arbitrary programs — all through the browser, all exfiltrated to the C2 server.

A MaaS Platform Expanding Quickly

LunexStealer and Psychedelic Stealer refer to the same component of a larger malware-as-a-service platform called Lunex. "Psychedelic" is the name of the executable that runs on victims' devices; Lunex is the underlying platform sold to multiple criminal groups. BlueTeamCoolTeam researcher Luke Wilkinson first identified six active Lunex C2 panels in June 2026 [4].

By the time Ontinue published its analysis in late September, that had grown to 28 unique panels across 13 countries. Panels were hosted in Russia, the US, the UK, the Netherlands, France, Germany, Turkey, and Bangladesh, among others. One panel hosted in Turkey resolved to five phishing domains impersonating brands including Sam's Club and WhatsApp Business, indicating the platform's feature set extends beyond credential theft to include active phishing operations. Panel code analysis pointed to a Russian-speaking developer or development team — an assessment based on language and code patterns, not definitive identification.

LUNARAXE Malicious Browser Extension — Module Breakdown (Conceptual) Three modules: LUNARAXE.CORE communicates with C2 server and executes remote commands in browser; LUNARAXE.STEALER captures login form data and sends to CORE; LUNARAXE.STRIP strips CSP headers from HTTP responses to allow arbitrary JavaScript injection. NAIVEMESS PowerShell host provides filesystem access. LUNARAXE — Malicious Browser Extension Modules LUNARAXE.CORE C2 communication Receives + executes commands Exfiltrates cookies, history, bookmarks, credentials Manages tabs, runs JS on web pages Displays overlay popups LUNARAXE.STEALER Captures credentials as typed into web forms Sends username, password, and page URL to CORE Works across all HTTP/HTTPS sites LUNARAXE.STRIP Removes CSP headers from HTTP responses Disables Content Security Policy protections Enables arbitrary JS injection on any page Conceptual diagram — LUNARAXE module structure. Disguises as "Microsoft Office Word Editor" | Source: Generated by UnpanicTech
Conceptual breakdown of the three LUNARAXE modules and their functions. The extension masquerades as "Microsoft Office Word Editor" in the browser extension list. Source: Generated by UnpanicTech.

What Defenders Should Do

CERT-UA's advisory included several concrete recommendations [1]. For organizations running Windows systems:

  • Prohibit standard users from accessing the Windows Run dialog via group policy. This cuts the ClickFix attack vector at the source — if the command can't be run, the chain never starts.
  • Restrict MSI package installation to users with administrator rights.
  • Monitor for msiexec.exe executions, particularly with remote URLs in the arguments.
  • Enable Microsoft's vulnerable driver blocklist — noting that Ontinue's testing found this did not block the specific PDFWKRNL.sys variant used here. Treat it as one layer, not a complete control.
  • Restrict browser extension installation to an organizational allowlist. This directly addresses LUNARAXE and the persistence it provides.

Microsoft separately recommends enabling the Attack Surface Reduction rule "Block abuse of exploited vulnerable signed drivers" to prevent applications from writing vulnerable signed drivers to disk [3].

The extension allowlisting point is worth emphasizing. Even if LunexStealer is detected and removed from a machine, LUNARAXE and NAIVEMESS can persist independently through the browser. Without extension controls in place, cleanup may be incomplete — and the attacker retains access through a component that many organizations aren't actively monitoring.

What Remains Unknown

CERT-UA confirmed the campaign was observed and identified the infrastructure, but did not state whether any systems were confirmed compromised or identify specific victims. The actual scale of infections is not established in public reporting. Attribution to UAC-0277 is CERT-UA's assessment; the cluster's relationship to any named group or state sponsor has not been publicly established in the sources reviewed here.

Which MSI variant gets deployed to any given victim may depend on operator configuration within the Lunex platform — meaning the severity of a specific infection can vary considerably, from a straightforward credential theft to a fully persistent browser implant with filesystem access.

The Bigger Picture on ClickFix

What makes this campaign worth watching beyond its Ukrainian targeting context is how mature ClickFix social engineering has become as a delivery mechanism. The UAC-0277 operation sits at the more sophisticated end: EtherHiding for resilient infrastructure, targeted filtering to avoid detection, BYOVD to neutralize endpoint security, and a layered persistence stack that can outlive cleanup efforts. It's not one clever trick — it's several working together.

The fundamental vulnerability here is user behavior, not a software flaw. Cloudflare verification pages appear on legitimate sites constantly, and that familiarity is exactly what the attack exploits. The defenses that matter most — blocking the Run dialog for standard users, restricting MSI installs, allowlisting extensions — are all policy controls rather than detection controls. They prevent the attack before any security tool needs to respond.

Sources & References

  1. CERT-UA Advisory #6319983 — UAC-0277 ClickFix on compromised websites distributing LUNEXSTEALER (September 2026)
  2. The Record — ClickFix campaign in Ukraine compromises over 100 websites to spread Lunex malware (Daryna Antoniuk, October 6, 2026)
  3. The Hacker News — 100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer (October 7, 2026)
  4. The Hacker News — Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials (September 26, 2026)
  5. Ontinue — Lunex Unmasked: A New Information Stealer Deployed Through BYOVD (Rhys Downing, September 24, 2026)
NK

Naseem Khan (Technical Editor)

Cybersecurity Researcher & Technical Editor

UnpanicTech is supported by a dedicated team of cybersecurity specialists and writers. All research and articles are comprehensively reviewed and published by our Technical Editor, Naseem Khan, covering vulnerability analysis, defensive security, incident response, cloud security, and practical security engineering.

Technical Discussion & Feedback

Leave a Comment (Authenticated Users)