More than 100 compromised websites have reportedly been used to show fake Cloudflare verification pages that push visitors into running commands on their own Windows machines. The campaign, reported by The Hacker News from a CERT-UA advisory, delivers LunexStealer, also known as Psychedelic Stealer, and shows why “prove you are human” pages have become a useful disguise for malware operators.
The practical takeaway is simple: a legitimate browser verification page should not ask a user to open the Windows Run dialog, paste a command, or install an MSI package. If a web page asks for that, treat it as hostile.
What happened
CERT-UA identified a campaign involving injected JavaScript on more than 100 compromised websites. When certain visitors reached those sites, they were shown a forged Cloudflare-style verification page. Instead of performing a normal browser challenge, the page instructed the user to execute a command. That command downloaded and installed a malicious MSI package from a remote server.
This is a form of the ClickFix technique: attackers present a fake problem, such as a failed verification or broken page access, and then provide step-by-step instructions that make the victim run the attacker’s payload manually. It is effective because it abuses trust, not only software flaws. The user is made to believe they are completing a routine security check.
The activity has been attributed by CERT-UA to the threat cluster UAC-0277. The reporting says the campaign was observed in September 2026, but it does not state which organizations or individual victims were successfully compromised.
Why the targeting matters
The injected script did not show the fake verification page to every visitor. According to the report, the campaign used operating modes controlled through blockchain-based infrastructure. Mode 0 was inactive, Mode 1 passively tracked visitors, and Mode 2 displayed the fake verification page.
In the active mode, the lure was shown only to Windows users who arrived from search engine results, and no more than twice within a 12-hour window. That selectivity matters for defenders. It means a quick manual visit to a suspected compromised page may not reproduce the malicious behavior. Security teams investigating affected websites should test with realistic referrer conditions, Windows user agents, and repeated-time controls in mind.
The campaign also used EtherHiding, a technique where attackers store or retrieve configuration details through smart contracts on blockchain networks such as Polygon or Ethereum. This can make takedown and blocking more difficult, because part of the attacker’s configuration is not hosted on a traditional command-and-control domain.
What LunexStealer does
LunexStealer is not just a one-step credential grabber. The reported infection chain includes multiple MSI variants and post-installation components.
One variant installs LunexStealer directly. Another attempts to bypass Windows User Account Control, adds Microsoft Defender exclusions, and abuses a legitimate but vulnerable AMD driver named PDFWKRNL.sys to interfere with security tools before retrieving the stealer. A third variant uses DLL sideloading, launching a legitimate executable named FnHotkeyUtility.exe so it loads a malicious DLL named spkvol.dll, which then decrypts and runs the stealer.
The malware is also associated with a malicious browser extension called LUNARAXE. That extension pretends to be “Microsoft Office Word Editor” and is designed to steal browser cookies, browsing history, credentials entered into web forms, and other browser data. It can also let the operator control browser behavior, inject JavaScript into pages, manage tabs, and display fake overlays.
Another component, NAIVEMESS, gives the extension access to the Windows file system through a PowerShell-based Native Messaging Host. That expands the impact from browser theft to file browsing, reading, writing, overwriting, archiving, and execution. In other words, once the browser extension and helper component are installed, the attacker may gain a bridge between web activity and local files.
Defensive steps for organizations
Organizations should treat this campaign as both an endpoint security issue and a user-behavior issue. Useful controls include:
- Block or restrict standard users from launching the Windows Run dialog where possible through Group Policy.
- Prevent non-admin users from installing MSI packages unless there is a clear business need.
- Monitor for suspicious msiexec.exe execution, especially when launched from browsers, scripting hosts, temporary directories, or recently downloaded files.
- Enable Microsoft’s vulnerable driver blocklist and consider Attack Surface Reduction rules, including the rule that blocks abuse of exploited vulnerable signed drivers.
- Restrict browser extension installation to an allowlist, especially on managed endpoints.
- Alert on unexpected Native Messaging Host registrations, new browser extensions, and PowerShell activity tied to browser processes.
- Review endpoint detections for Defender exclusion changes, UAC bypass behavior, and suspicious driver loading.
For web teams, the incident is also a reminder to monitor websites for unauthorized JavaScript injection. File integrity monitoring, Content Security Policy, dependency review, admin panel hardening, and rapid patching of CMS plugins can reduce the chance that a legitimate site becomes part of someone else’s malware delivery network.
What users should remember
Cloudflare and similar services may ask users to click, wait, or complete a browser-based challenge. They should not require a command pasted into Windows, an MSI installer, or changes to local security settings. If a page gives those instructions, close it and report the site to IT or the site owner.
The campaign is notable because it combines several modern attacker preferences: compromised legitimate websites, fake verification pages, selective targeting, blockchain-hosted configuration, MSI installers, vulnerable driver abuse, browser extension theft, and social engineering. None of those pieces are new on their own, but together they create an infection path that can evade casual inspection and relies on the user doing exactly what the page says.
Source: The Hacker News source