Threat actors have compromised more than 100 legitimate websites and are leveraging counterfeit Cloudflare verification prompts to deliver LUNEXSTEALER, a sophisticated Windows-based malware strain capable of stealing sensitive data and executing remote commands on infected systems.
The campaign transforms trusted websites into malware delivery platforms by injecting malicious JavaScript into site pages. Visitors are presented with what appears to be a routine Cloudflare security check, but the prompt is actually part of a carefully crafted infection chain designed to compromise Windows devices.
Rather than relying on traditional phishing attachments or malicious downloads, the attackers employ a social engineering technique widely known as ClickFix. Victims are instructed to manually execute a command under the guise of verifying they are human, making the malicious action appear legitimate and reducing suspicion.
Researchers from CERT-UA identified and tracked the operation during September 2026 under the designation UAC-0277. Their investigation revealed multiple malware deployment methods being used to infect visitors and maintain operational flexibility.
Once installed, LUNEXSTEALER can harvest a wide range of sensitive information, including saved browser credentials, authentication tokens, cryptocurrency wallet contents, device details, and other valuable system data. However, the threat extends far beyond credential theft.
Because the malware supports remote command execution, attackers can download additional payloads, launch arbitrary programs, and further expand control over compromised machines. The exact number of infected victims remains unknown.
Fake Cloudflare Pages Used as Initial Access Vector
Visitors arriving at compromised websites encounter a fraudulent verification page claiming that a security check is required before proceeding. The page instructs users to run a command on their systems to confirm they are legitimate visitors.
Executing the command triggers the download and installation of a Windows MSI package hosted on attacker-controlled infrastructure. By convincing users to perform the action themselves, the attackers effectively bypass many traditional security warnings that commonly accompany suspicious downloads.
.webp)
The malicious JavaScript embedded within compromised websites retrieves configuration data from smart contracts hosted on the Polygon and Ethereum blockchains. This approach allows operators to dynamically modify campaign settings and redirect victims without needing to revisit every compromised website.
Researchers identified three primary operational modes:
- Inactive Mode – No malicious activity is performed.
- Tracking Mode – Visitor and referral information is quietly transmitted to attacker infrastructure.
- Verification Mode – The fake Cloudflare challenge is displayed and infection attempts are initiated.
Tracking mode collects intelligence such as the compromised website address and referring source, providing attackers with insight into victim acquisition channels and campaign effectiveness.
To evade detection and reduce exposure, the fake verification page is shown only under specific circumstances. Targeting primarily focuses on Windows users arriving via search engines such as Google and DuckDuckGo. Additionally, the prompt appears no more than twice within a 12-hour window, making the attack far less noticeable.
Multiple Malware Delivery Techniques Observed
Researchers documented three separate installer variants used throughout the campaign.
One version deploys LUNEXSTEALER directly onto the victim system.
A second variant utilizes a loader designed to weaken endpoint defenses before installing the payload. The loader attempts to:
- Bypass Windows User Account Control (UAC)
- Add exclusion rules to Microsoft Defender
- Exploit CVE-2023-20598 through a vulnerable AMD driver
- Disable or interfere with security-related software
This technique reflects a growing trend in cybercrime operations where attackers abuse legitimately signed but vulnerable drivers to undermine endpoint security mechanisms.
The third installation method relies on DLL side-loading. A legitimate executable is launched alongside a malicious library, which subsequently decrypts and executes the LUNEXSTEALER payload in memory.
LUNARAXE Browser Extension Expands Attacker Capabilities
Depending on instructions received from its command-and-control infrastructure, LUNEXSTEALER can install an additional Chromium-based browser extension known as LUNARAXE.
The extension disguises itself as a document editing utility while secretly collecting:
- Browser cookies
- Browsing history
- Saved bookmarks
- Login credentials entered into web forms
Beyond data theft, LUNARAXE provides substantial browser-level control. Attackers can:
- Open, close, and manipulate browser tabs
- Capture screenshots
- Modify proxy settings
- Execute arbitrary JavaScript within webpages
- Monitor and alter user browsing activity
These capabilities effectively allow threat actors to observe victim activity in real time and potentially manipulate content displayed in the browser.
NAIVEMESS Bridges Browser Access to the Operating System
Researchers also identified a supporting PowerShell component named NAIVEMESS, which acts as a bridge between the malicious browser extension and the Windows operating system.
Through this component, attackers can:
- Browse directories
- Read files
- Modify stored data
- Create new files
- Launch executable programs
A separate extension module further weakens browser security by disabling website protections that restrict script execution and data transfers.
Communication between infected systems and attacker infrastructure primarily occurs over HTTP, while WebSocket functionality enables interactive remote control sessions through the browser extension.
To maintain persistence, the malware survives browser restarts and may create scheduled tasks that automatically relaunch components after system reboots.
CERT-UA Recommendations
CERT-UA warns that legitimate human verification systems never require users to open the Windows Run dialog, Command Prompt, or PowerShell and manually execute commands.
Users should immediately close any page that requests such actions, regardless of how trustworthy the website appears.
Organizations are advised to:
- Restrict access to the Windows Run dialog through Group Policy
- Prevent MSI package installation by non-administrative users
- Monitor installer execution involving URLs or remote resources
- Enable Microsoft's vulnerable driver blocklist
- Restrict browser extensions to approved and trusted add-ons
- Investigate and report suspected fake verification pages
Website owners who discover signs of compromise are encouraged to conduct a thorough forensic review and work with CERT-UA to identify the initial intrusion vector and remove malicious code from affected systems.
Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post.
