CERT-UA: 100+ Sites Hijacked to Drop LunexStealer
Ukraine's CERT-UA tracked 100+ compromised sites serving LunexStealer through fake Cloudflare verification pages. Attributed to UAC-0277, observed September 2026.

100+ compromised websites were confirmed by CERT-UA injecting malicious JavaScript to deliver an information stealer called LunexStealer (also documented as Psychedelic Stealer). The campaign is attributed to UAC-0277. Observation period: September 2026. Source: The Hacker News, citing the CERT-UA advisory directly.
How the attack works
Visitors to compromised sites encounter a fake Cloudflare DDoS-protection or browser-verification page. This is the ClickFix technique. Windows users who follow the on-screen prompt execute a command that fetches a malicious MSI package. The fake check fires only for Windows users, at most twice per visitor per 12-hour window. That throttle keeps detection noise low.
Campaign infrastructure relies on EtherHiding: the C2 configuration is retrieved from smart contracts on the Polygon and Ethereum blockchains rather than from a conventional server. Three modes govern campaign state. Mode 0 disables activity. Mode 1 passively tracks visitors. Mode 2 activates the fake verification page.
What LunexStealer takes
The stealer targets browser-stored data: cookies, browsing history, saved credentials, form data, and installed extension lists.
A browser extension component named LUNARAXE impersonates “Microsoft Office Word Editor.” Once installed, it gives UAC-0277 remote control over the compromised browser, including the ability to run arbitrary JavaScript in the victim’s browser session.
Four named components make up the toolkit. LUNARAXE.CORE handles C2 communication. LUNARAXE.STEALER intercepts credentials. LUNARAXE.STRIP disables Content Security Policy protections. NAIVEMESS provides file system access through a PowerShell Native Messaging Host.
Variants and evasion
Three MSI package variants exist, escalating in sophistication. The most capable includes a UAC bypass, adds exceptions to Microsoft Defender, loads a signed but vulnerable AMD kernel driver (PDFWKRNL.sys) to execute code in kernel context, and uses DLL sideloading.
Blockchain-based C2 configuration makes infrastructure takedowns harder than standard domain-based approaches. The specific vulnerabilities in the 100+ compromised sites that allowed JavaScript injection have not been publicly disclosed.
CERT-UA mitigations
CERT-UA’s published guidance:
- Restrict or monitor access to the Windows Run dialog (Win+R).
- Block execution of unsigned MSI packages via Windows policy.
- Monitor for unexpected msiexec.exe processes.
- Enable the Windows vulnerable driver blocklist through WDAC or Defender.
- Limit browser extension installation to an organization-approved list.
No CVE is attached to LunexStealer. The infection vector is user execution, not an unpatched vulnerability. Environments with application allowlisting, unsigned-MSI blocking, and extension controls in place are less exposed.
Related: Rejetto HFS RCE Under Active Exploitation | AI Agents Fired 200K Requests at Gov Sites | Pwn2Own Ireland: 32 Zero-Days on Day One
Found this useful? Share it.


