Ukraine’s Computer Emergency Response Team (CERT-UA) has discovered more than 100 compromised websites being used to distribute an information-stealing malware known as LunexStealer, also called Psychedelic Stealer.

The campaign was observed in September 2026 and has been linked to a threat group tracked as UAC-0277.

The affected websites were injected with malicious JavaScript that displays a fake Cloudflare verification page to selected visitors. Instead of simply verifying that a visitor is human, the fraudulent page instructs users to run a command on their Windows computer. Following the instructions triggers the download and installation of a malicious MSI package hosted on a remote server, using a technique known as ClickFix.

CERT-UA said the campaign also uses EtherHiding to retrieve information from blockchain smart contracts. The attackers use smart contracts on the Polygon or Ethereum networks to store the domain used to load the fake verification page as well as instructions controlling how the injected script operates.

The malicious script has three modes. Mode 0 keeps the activity inactive, while Mode 1 passively tracks visitors and collects information about the website and the page that referred them. Mode 2 activates the fake verification page and is used to deliver the malware.

The fake verification screen is selectively displayed to Windows users who reach the compromised website through search engine results. CERT-UA said the page is shown no more than twice to the same visitor within 12 hours, helping the attackers make the activity less obvious.

READ
Apple CoreGraphics Zero-Day Gets First Public Exploit Demo

Researchers have identified at least three different MSI package variants used in the campaign. The first simply installs LunexStealer on the victim’s computer. The second attempts to bypass Windows User Account Control, creates exclusions in Microsoft Defender, and abuses a legitimate but vulnerable AMD driver called PDFWKRNL.sys to interfere with security protections before downloading and executing LunexStealer from a remote server.

The third variant uses DLL sideloading to launch the malware. It relies on the legitimate FnHotkeyUtility.exe executable to load a malicious DLL named spkvol.dll, which then decrypts and runs LunexStealer.

LunexStealer can also install a malicious browser extension called LUNARAXE. The extension disguises itself as “Microsoft Office Word Editor” and is designed to steal browser cookies, browsing history and credentials entered into web forms. Attackers can also use it to remotely control the browser and execute JavaScript inside web pages.

The malware deploys another component called NAIVEMESS depending on instructions received from its command-and-control server. NAIVEMESS gives the malicious browser extension access to the Windows file system through a PowerShell-based Native Messaging Host.

CERT-UA said the component can list drives, browse directories, read, create and overwrite files, and execute files on the compromised machine. Files can be transferred in Base64-encoded chunks, while directories and groups of files can be packaged into ZIP archives.

The LUNARAXE extension contains several modules that work together. LUNARAXE.CORE handles communication with the attackers, processes commands and steals browser information such as cookies, history, bookmarks, installed extensions and captured credentials. It can also manage browser tabs, control extensions, display notifications and fake overlays, and execute JavaScript on websites.

READ
WordPress Backdoor Can Rebuild Itself After Cleanup Using Eight Persistence Layers

LUNARAXE.STEALER focuses on capturing credentials entered into web forms and sending them to the core module along with the URL of the affected page. Another component, LUNARAXE.STRIP, removes Content Security Policy protections from HTTP responses, allowing the attackers to run arbitrary JavaScript on targeted pages.


Buy ExpressVPN with PayPal or Credit Card

CERT-UA is advising organizations to restrict access to the Windows Run dialog for standard users through Group Policy and prevent users without administrator privileges from installing MSI packages. Organizations should also monitor for suspicious execution of msiexec.exe, enable Microsoft’s vulnerable driver blocklist and restrict browser extension installations to approved extensions.

Advertisement