100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer
Over 100 websites have been compromised with malicious JavaScript to distribute LunexStealer malware. Attackers use fake Cloudflare verification pages to trick users into downloading MSI packages containing the stealer.
Intelligence analysis by Gemini 2.5 Flash Lite

A sophisticated campaign, attributed to threat cluster UAC-0277, has compromised over 100 websites. These sites display fake Cloudflare verification pages to lure visitors into executing commands that download malicious MSI packages. These packages deploy LunexStealer, an information-stealing malware, which can also install a malicious browser extension called LUNARAXE to steal cookie…
Imagine bad guys hide a fake security check on over 100 websites. When you visit, it looks like a real check from Cloudflare, a company that helps websites. If you click it, it tricks your computer into downloading a secret spy program that steals your passwords and browsing history.
Analysis
UAC-0277's Evolving Tactics
The threat cluster UAC-0277 has demonstrated a multi-faceted approach to malware distribution, leveraging compromised websites to serve the LunexStealer. The initial vector involves injecting malicious JavaScript into legitimate sites, which then presents a forged Cloudflare verification page. This page, designed to appear legitimate, prompts users to execute a command under the guise of a human verification process. This 'ClickFix' technique is a clever social engineering ploy that bypasses typical user caution by mimicking a trusted security measure.
Once the user executes the command, a malicious MSI package is downloaded from a remote server. The article details three distinct variants of these MSI packages, each employing different evasion and execution strategies. Variant 1 is straightforward, installing LunexStealer directly. Variant 2 goes further by attempting to bypass Windows User Account Control (UAC), configuring Microsoft Defender exclusions, and exploiting a legitimate but vulnerable AMD driver to evade detection before fetching and running the stealer. Variant 3 utilizes DLL sideloading, a technique where a legitimate executable loads a malicious DLL, to execute the stealer, further obscuring its malicious intent.
LunexStealer and LUNARAXE Capabilities
LunexStealer itself is a potent information-stealing malware, capable of exfiltrating sensitive data. However, its functionality is significantly amplified by the LUNARAXE browser extension, which it can install. LUNARAXE, masquerading as a legitimate Microsoft Office tool, is designed to steal cookies, browsing history, and credentials entered into web forms. It also grants operators remote control over the user's browser, allowing for the execution of arbitrary JavaScript and the display of deceptive overlays. This dual threat of a system-level stealer and a sophisticated browser extension creates a comprehensive data harvesting operation.
Furthermore, LunexStealer deploys an auxiliary component called NAIVEMESS. This component, installed based on configuration from the command-and-control (C2) server, provides LUNARAXE with deep access to the Windows file system via a PowerShell-based Native Messaging Host. NAIVEMESS can list drives, browse directories, read, create, and overwrite files, and even execute them. Data is transferred in Base64 encoded chunks, and directories are pre-archived into ZIP files, indicating a structured approach to data exfiltration.
EtherHiding and Operational Modes
A particularly innovative aspect of this campaign is the use of the EtherHiding technique. This method allows the malicious script to retrieve its operating mode and the domain of the fake verification page from a smart contract on the Polygon or Ethereum blockchain. This decentralized approach to configuration management makes it harder for security analysts to track and disrupt the campaign. The smart contract defines three operating modes: Mode 0 is inactive, Mode 1 involves passive visitor tracking and data gathering about the website and referral source, and Mode 2 is the active mode where the fake verification page is displayed.
Interestingly, Mode 2 is specifically targeted. It is only displayed to Windows users who arrive at the compromised site via search engine results, and it is limited to a maximum of twice every 12 hours. This targeted approach aims to maximize the chances of success by appearing less suspicious and more relevant to the user's browsing context, thereby increasing the likelihood of them falling for the social engineering trick and downloading the malicious MSI package.
Key points
- Over 100 websites have been compromised by threat cluster UAC-0277 to distribute LunexStealer malware.
- Attackers use fake Cloudflare verification pages (ClickFix technique) to trick users into downloading malicious MSI packages.
- LunexStealer can install the LUNARAXE browser extension, stealing credentials, cookies, and controlling browser activity.
- The campaign utilizes EtherHiding to retrieve configuration from blockchain smart contracts.
- Security recommendations include restricting user execution of MSI packages and monitoring for suspicious driver usage.
The detailed analysis and advisories from CERT-UA and other security researchers provide valuable intelligence for defenders. By understanding the specific techniques like ClickFix and EtherHiding, organizations can implement targeted defenses and improve their ability to detect and block LunexStealer and similar threats.
The widespread compromise of over 100 websites and the sophisticated evasion techniques employed by UAC-0277 indicate a significant and ongoing threat. Without prompt patching and user education, many individuals and organizations remain vulnerable to data theft and system compromise.


