A campaign that uses more than 100 compromised websites to distribute LUNEXSTEALER, a Windows infostealer that installs a browser extension giving attackers remote control.
The extension, LUNARAXE, masquerades as “Microsoft Office Word Editor” inside Chromium-based browsers.
Beyond stealing cookies, browsing history, and credentials entered into forms, it enables operators to execute JavaScript within webpages, manipulate tabs, capture snapshots, and change browser proxy settings.
An auxiliary component extends that access to the underlying Windows filesystem.
Attackers injected malicious JavaScript into legitimate websites, presenting visitors with counterfeit Cloudflare verification pages.
The pages instructed users to execute a command supposedly needed to confirm they were human.
Instead, the command downloaded and installed a malicious MSI package from an attacker-controlled server.
The injected script retrieves its delivery domain and operating mode from smart contracts on Polygon or Ethereum.
This blockchain-backed configuration lets operators centrally redirect the campaign without modifying every compromised website again.
CERT-UA described three modes: inactive, passive visitor tracking, and active delivery of the fake verification page.
Active delivery selectively targeted Windows visitors arriving through search engines, including Google, DuckDuckGo, meta.ua, and bigmir.net.
The fake challenge appeared no more than twice within 12 hours, limiting repeated exposure while filtering traffic for potential victims. Passive tracking collected the visited website and referring page information.
CERT-UA investigated three MSI variants. The first installed LUNEXSTEALER directly.
CERT-UA Researchers discovered that, the activity is tracked as UAC-0277 and combines ClickFix social engineering with multiple malware delivery techniques.
The second deployed a loader that attempted to bypass Windows User Account Control, added Microsoft Defender exclusions, and introduced the vulnerable AMD PDFWKRNL.sys driver before retrieving the stealer from a remote server.
That driver is affected by CVE-2023-20598, an improper privilege-management vulnerability permitting potentially dangerous access to hardware ports or physical addresses.
The campaign abuses it through bring-your-own-vulnerable-driver techniques. The third MSI variant uses DLL side-loading: legitimate FnHotkeyUtility.exe loads malicious spkvol.dll, which decrypts and launches LUNEXSTEALER.
The 64-bit payload steals browser passwords, tokens, cryptocurrency-wallet data, and system information. It also executes downloaded programs, MSI packages, PowerShell scripts, and command-shell instructions.
Server-provided configuration determines whether it deploys LUNARAXE, installs NAIVEMESS, or establishes persistence through the scheduled task “psychedelicloveUtils.” Its management traffic uses HTTP.
LUNARAXE.CORE handles command execution and data collection, communicating over HTTP and WebSocket.
LUNARAXE.STEALER intercepts login and password fields when users submit forms, forwarding captured values and page addresses internally.
LUNARAXE.STRIP removes Content Security Policy headers and corresponding HTML metadata, potentially weakening restrictions against injected scripts and unauthorized data transfers.
NAIVEMESS registers a PowerShell-based Native Messaging host named “com.lunex.explorer.”
Through this browser-to-native communication channel, attackers can enumerate drives, browse directories, read or overwrite files, and launch them. File transfers use Base64 chunks, with directories and grouped files archived as ZIP.
Commands arrive through the extension rather than an independent control channel.
CERT-UA recommends restricting the Windows Run dialog, controlling MSI installation, monitoring msiexec.exe commands containing URLs, enabling vulnerable-driver blocking, and enforcing browser-extension allowlists.
Its campaign advisory provides further context. Legitimate verification never requires executing commands; users should close such pages, while website owners should report suspected compromises promptly to CERT-UA.
| Network | Host |
|---|---|
107[.]175.82.242 | %PROGRAMDATA%/SalmonLightSlateGray/FnHotkeyUtility.exe |
193[.]178.158.61 | %PROGRAMDATA%/SalmonLightSlateGray/spkvol.dll |
193[.]178.159.128 | %PROGRAMDATA%\SlateGrayChocolate\spkvol.dll |
109[.]238.86.112 | %PROGRAMDATA%\GrayLightCyan\FnHotkeyUtility.exe |
109[.]238.86.113 | %PROGRAMDATA%\GrayLightCyan\spkvol.dll |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…