HomeSecurity100+ sites with fake Cloudflare check distribute LunexStealer

100+ sites with fake Cloudflare check distribute LunexStealer

LunexStealer , also known as Psychedelic Stealer , is at the center of a new cyberattack campaign detected by CERT-UA (Computer Emergency Response Team of Ukraine) in September 2026. According to The Hacker News , over 100 legitimate websites have been compromised and malicious JavaScript code has been injected into them, with the aim of deceiving visitors via fake Cloudflare verification pages. The activity is attributed to the UAC-0277 threat group and is a sophisticated example of social engineering, exploiting users’ trust in well-known security platforms.

LunexStealer malware fake Cloudflare CAPTCHA ClickFix

The campaign leverages the ClickFix, a social engineering method in which victims are convinced that they need to execute a command to resolve a technical issue or complete a verification process. In this case, the fake page visually mimics the well-known Cloudflare and asks the user to copy and execute a command via the Windows Run dialog or PowerShell. Executing this command downloads and installs a malicious MSI package from a remote server.

It is worth noting that the campaign also uses the EtherHiding technique , which retrieves the domain name of the malicious resource from a smart contract on the Polygon or Ethereum network . This approach makes it extremely difficult to block the attackers’ infrastructure, as the decentralized nature of the blockchain prevents traditional domain takedowns.

CERT -UA identified three operational states: inactive (0), passive visitor tracking (1), and displaying the fake verification page (2).

See also: Lunex Stealer: New malware exploits AMD driver

How LunexStealer and the ClickFix technique work

In operational mode 2, the fake verification page is only displayed to Windows who reach the site through search engine results, and no more than twice within a 12-hour. This selective targeting makes it difficult for security researchers who visit the compromised sites directly to detect it.

CERT-UA emphasized that legitimate Cloudflare never require users to open Win+R, launch PowerShell , or run system commands. These ClickFix decoys lead to the distribution of MSI packages that install LunexStealer.

At least three different variants of the MSI packages were detected . The first variant simply installs LunexStealer on the system. The second variant is more sophisticated: it attempts to bypass Windows User Account Control ( UAC ) , configures exceptions in Microsoft Defender , exploits a legitimate but vulnerable AMD driver ( PDFWKRNL.sys ) to "blind" security software, and then retrieves and executes LunexStealer from a remote server. The third variant launches LunexStealer via DLL sideloading , using the legitimate executable FnHotkeyUtility.exe to load a malicious DLL ( spkvol.dll ), which decrypts and executes the stealer .

LunexStealer - SecNews.gr

The use of legitimate but vulnerable drivers to bypass security software — a technique known as BYOVD (Bring Your Own Vulnerable Driver) — is a worrying trend that is increasingly being seen in sophisticated attacks. In this way, attackers can disable or solutions EDR and antivirus, effectively gaining a “blind spot” in the system’s defenses.

LunexStealer and the malicious LUNARAXE extension

LunexStealer is designed to install a malicious browser extension called LUNARAXE , according to reports from Arctic Wolf Labs and Ontinue . The extension is presented as a “ Microsoft Office Word Editor” to appear legitimate, while in reality it steals cookies, browsing history, and credentials entered into web forms. It also allows the operator to remotely control the browser and execute arbitrary JavaScript on web pages.

See also: Silver Fox Group Deploys Sainbox RAT via Fake Websites

LunexStealer deploys a utility called NAIVEMESS, which is installed based on a configuration received from the command and control (C2) server. NAIVEMESS's main role is to provide LUNARAXE with access to the file system Windows via a PowerShell-based Native Messaging Host. Its functions include retrieving disk listings, browsing directories, reading, creating, and replacing files, as well as executing them. Files are transferred in Base64, while directories and groups of files are pre-archived in ZIP.

The LUNARAXE extension consists of three sub-modules. LUNARAXE.CORE manages communication with the C2 server, receives commands, executes them and extracts browser data (cookies, history, bookmarks, details of installed extensions and intercepted credentials). It can also manage tabs, enable/disable extensions, execute JavaScript on web pages and display fake overlays. LUNARAXE.STEALER captures credentials entered in web forms and sends them to LUNARAXE.CORE along with the page URL. Finally, LUNARAXE.STRIP disables Content Security Policy (CSP) protections on web pages, opening the way for further attacks .

How to protect yourself from LunexStealer and similar attacks

Organizations and individuals can take specific steps to reduce the risk of infection by LunexStealer and similar campaigns. First of all, it is critical to understand that no legitimate security checks — including Cloudflare — require executing commands via PowerShell or Windows Run. If a website asks for this, it is almost certainly a scam.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Technically, organizations should restrict or block PowerShell for users who do not need it, using application control policies and Constrained Language Mode. Enabling the Microsoft VulnerableDriver Blocklistand Windows Defender Application Control can prevent BYOVD. Additionally, deploying allowlisting for browser extensions and only allowing approved extensions through corporate policies can prevent the installation of malicious extensions like LUNARAXE.

Article image: Beware these fake websites selling subscriptions to AI assistants

See also: CVE-2026-12523: DoS via resource exhaustion in Cloudflare quiche (HTTP/3)

Security teams should monitor for suspicious activity, such as PowerShell launching immediately after a browser process, downloads from low-reputation domains, installation of extensions outside of approved channels, unusual access to browser profile databases (Chrome, Edge, Firefox), and outbound PowerShell to unknown infrastructure. Implementing phishing-resistant MFA for administrator accounts and regularly updating all software — including CMS, plugins, and operating systems — remain fundamental defense practices against campaigns like the one distributing LunexStealer.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS