The Computer Emergency Response Team of Ukraine (CERT-UA) has revealed a new cybersecurity threat affecting over 100 websites. These sites have been infiltrated with harmful JavaScript code designed to deploy an information-stealing malware known as LunexStealer, also referred to as Psychedelic Stealer.
Discovery of Malicious Activity
In September 2026, CERT-UA identified this malicious activity, attributing it to a group known as UAC-0277. However, details about the specific individuals or systems targeted remain undisclosed. The attackers utilized counterfeit Cloudflare verification pages to deceive users into executing commands that install malware.
The fraudulent verification pages, appearing genuine, prompt users to download and run a harmful MSI package via the ClickFix technique. This method disguises the malware as a legitimate security check, tricking unsuspecting visitors into compromising their systems.
Techniques and Variants Used
Attackers employed the EtherHiding technique to obscure the origin of the malicious scripts, using smart contracts on blockchain networks like Polygon and Ethereum. The campaign operates in three distinct modes: inactive, passive data collection, and active malware deployment.
The active deployment, or Mode 2, targets Windows users who access these compromised sites through search engine results, limiting exposure to twice within 12 hours. The attackers utilized three MSI package variants, each with unique methods for installing LunexStealer and evading security measures.
Impact and Mitigation Strategies
LunexStealer is designed to install a fraudulent browser extension named LUNARAXE, which poses as a legitimate Microsoft Office tool. This extension captures sensitive data like cookies and credentials, providing attackers with remote browser control.
Additionally, an auxiliary component called NAIVEMESS facilitates file system access, enhancing LUNARAXE’s capabilities. CERT-UA advises organizations to implement security measures such as restricting MSI package installations and monitoring for unauthorized software executions.
Microsoft further recommends enabling specific security policies, like the Attack Surface Reduction (ASR) rule, to prevent the installation of vulnerable drivers that could be exploited by such threats.
Organizations are urged to strengthen their cybersecurity protocols to combat these sophisticated threats effectively. Continuous monitoring and updating of security systems are crucial steps in safeguarding against such pervasive malware campaigns.
