Cyber Security News

LUNEXSTEALER Gives Hackers Remote Control of Browsers Through Malicious Chrome Extension

A campaign that uses more than 100 compromised websites to distribute LUNEXSTEALER, a Windows infostealer that installs a browser extension giving attackers remote control.

The extension, LUNARAXE, masquerades as “Microsoft Office Word Editor” inside Chromium-based browsers.

Beyond stealing cookies, browsing history, and credentials entered into forms, it enables operators to execute JavaScript within webpages, manipulate tabs, capture snapshots, and change browser proxy settings.

An auxiliary component extends that access to the underlying Windows filesystem.

Attackers injected malicious JavaScript into legitimate websites, presenting visitors with counterfeit Cloudflare verification pages.

The pages instructed users to execute a command supposedly needed to confirm they were human.

Instead, the command downloaded and installed a malicious MSI package from an attacker-controlled server.

The injected script retrieves its delivery domain and operating mode from smart contracts on Polygon or Ethereum.

This blockchain-backed configuration lets operators centrally redirect the campaign without modifying every compromised website again.

CERT-UA described three modes: inactive, passive visitor tracking, and active delivery of the fake verification page.

Active delivery selectively targeted Windows visitors arriving through search engines, including Google, DuckDuckGo, meta.ua, and bigmir.net.

The fake challenge appeared no more than twice within 12 hours, limiting repeated exposure while filtering traffic for potential victims. Passive tracking collected the visited website and referring page information.

Example of a malicious script on a compromised website (Source : CERT-UA).

CERT-UA investigated three MSI variants. The first installed LUNEXSTEALER directly.

CERT-UA Researchers discovered that, the activity is tracked as UAC-0277 and combines ClickFix social engineering with multiple malware delivery techniques.

LUNEXSTEALER Hijacks Browsers

The second deployed a loader that attempted to bypass Windows User Account Control, added Microsoft Defender exclusions, and introduced the vulnerable AMD PDFWKRNL.sys driver before retrieving the stealer from a remote server.

That driver is affected by CVE-2023-20598, an improper privilege-management vulnerability permitting potentially dangerous access to hardware ports or physical addresses.

Example of a fake Cloudflare verification page (Source : CERT-UA).

The campaign abuses it through bring-your-own-vulnerable-driver techniques. The third MSI variant uses DLL side-loading: legitimate FnHotkeyUtility.exe loads malicious spkvol.dll, which decrypts and launches LUNEXSTEALER.

The 64-bit payload steals browser passwords, tokens, cryptocurrency-wallet data, and system information. It also executes downloaded programs, MSI packages, PowerShell scripts, and command-shell instructions.

Server-provided configuration determines whether it deploys LUNARAXE, installs NAIVEMESS, or establishes persistence through the scheduled task “psychedelicloveUtils.” Its management traffic uses HTTP.

LUNARAXE.CORE handles command execution and data collection, communicating over HTTP and WebSocket.

LUNARAXE.STEALER intercepts login and password fields when users submit forms, forwarding captured values and page addresses internally.

LUNARAXE.STRIP removes Content Security Policy headers and corresponding HTML metadata, potentially weakening restrictions against injected scripts and unauthorized data transfers.

NAIVEMESS registers a PowerShell-based Native Messaging host named “com.lunex.explorer.”

Through this browser-to-native communication channel, attackers can enumerate drives, browse directories, read or overwrite files, and launch them. File transfers use Base64 chunks, with directories and grouped files archived as ZIP.

Commands arrive through the extension rather than an independent control channel.

CERT-UA recommends restricting the Windows Run dialog, controlling MSI installation, monitoring msiexec.exe commands containing URLs, enabling vulnerable-driver blocking, and enforcing browser-extension allowlists.

Its campaign advisory provides further context. Legitimate verification never requires executing commands; users should close such pages, while website owners should report suspected compromises promptly to CERT-UA.

IOCs

NetworkHost
107[.]175.82.242%PROGRAMDATA%/SalmonLightSlateGray/FnHotkeyUtility.exe
193[.]178.158.61%PROGRAMDATA%/SalmonLightSlateGray/spkvol.dll
193[.]178.159.128%PROGRAMDATA%\SlateGrayChocolate\spkvol.dll
109[.]238.86.112%PROGRAMDATA%\GrayLightCyan\FnHotkeyUtility.exe
109[.]238.86.113%PROGRAMDATA%\GrayLightCyan\spkvol.dll

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

Mayura Kathir

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

3 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago