Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
SonicWall Patches Critical Pre-Auth SSRF (CVE-2024-XXXX) in SMA1000
October 7, 2026
Hackers Breach South Korean Churches, Exposing 1 Million Members’ Data
October 7, 2026
FBI Warns of Critical FortiBleed Attacks Exploiting Fortinet Firewalls and VPNs
October 7, 2026
Home/CyberSecurity News/Fake Cloudflare CAPTCHAs Spread LUNEXSTEALER to 100+ Websites
CyberSecurity News

Fake Cloudflare CAPTCHAs Spread LUNEXSTEALER to 100+ Websites

Key Takeaways Over 100 websites were compromised to distribute LUNEXSTEALER, a Windows information-stealing malware. The attack leverages fake Cloudflare CAPTCHA pages, prompting users to execute a...

Emy Elsamnoudy
Emy Elsamnoudy
October 7, 2026 5 Min Read
3 0

Key Takeaways

  • Over 100 websites were compromised to distribute LUNEXSTEALER, a Windows information-stealing malware.
  • The attack leverages fake Cloudflare CAPTCHA pages, prompting users to execute a command to bypass the “security check.”
  • LUNEXSTEALER collects sensitive data like browser passwords, crypto wallet information, and system details, and can install a malicious browser extension, LUNARAXE.
  • The campaign, identified as UAC-0277 by CERT-UA, employs sophisticated techniques, including exploiting a vulnerable AMD driver (CVE-2023-20598) and using blockchain smart contracts for command and control.
  • Users should be highly suspicious of any CAPTCHA or security prompt that requires executing commands in the Windows Run dialog, command prompt, or PowerShell.

Cybercriminals have successfully breached more than 100 websites, deploying deceptive Cloudflare verification pages to disseminate LUNEXSTEALER, a potent Windows-based information-stealing malware. This widespread campaign transforms routine website visits into opportunities for system compromise, as detailed in a recent report.

Table Of Content

  • Key Takeaways
  • LUNEXSTEALER’s Capabilities and Evasion Techniques
  • Browser Takeover with LUNARAXE
  • What You Should Do

The attackers injected malicious JavaScript into legitimate website pages. This script then presented a convincing, yet fake, Cloudflare security challenge. Unlike typical CAPTCHAs, this fraudulent prompt instructed users to execute a specific command to “verify” their humanity, a tactic designed to bypass traditional security awareness against suspicious downloads. This method, often referred to as ClickFix, manipulates users into initiating the infection themselves, rather than relying on them to open an obvious attachment.

CERT-UA researchers, who began tracking this activity as UAC-0277 in September 2026, analyzed three distinct installer variants used to deliver the LUNEXSTEALER malware. Their report shared with Cyber Security News (CSN) on September 30, 2026, highlighted the malware’s extensive capabilities.

LUNEXSTEALER’s Capabilities and Evasion Techniques

LUNEXSTEALER is designed to harvest a wide array of sensitive data, including saved browser passwords, authentication tokens, cryptocurrency wallet data, and detailed system information. Its remote execution features further escalate the threat, enabling attackers to download and install additional software and issue arbitrary commands on compromised systems. The full extent of victim compromise remains undetermined by the advisory.

The malicious script’s operational parameters and verification domain were dynamically retrieved from a smart contract hosted on either the Polygon or Ethereum blockchain networks. This innovative command-and-control mechanism allows the attackers to centrally modify the campaign’s behavior and target domains without needing to individually update the code on each compromised website.

The campaign operates in three modes: inactive, passive visitor tracking, and active fake verification display. In passive mode, the script gathers information about the compromised website and the referring page, sending it to the attacker’s infrastructure. The active mode, however, is where the deceptive CAPTCHA challenge is presented to the user.

This fake verification page was selectively displayed. It targeted only Windows users who arrived at the compromised sites via search engines such as Google and DuckDuckGo. To avoid detection and maintain stealth, the prompt appeared a maximum of twice within a 12-hour period, ensuring a measured and less aggressive exposure to potential victims.

One of the identified installer variants directly deployed LUNEXSTEALER. Another employed a loader designed to bypass Windows User Account Control (UAC), establish exclusions within Microsoft Defender, and exploit CVE-2023-20598 in a vulnerable AMD driver (PDFWKRNL.sys version 0.0.0.1) to interfere with security tools. This tactic of abusing legitimate but flawed drivers has been observed in other sophisticated attacks seeking to undermine system defenses. A third installer variant utilized a legitimate executable, FnHotkeyUtility.exe, to side-load a malicious library, spkvol.dll, which then decrypted and launched the stealer component.

Browser Takeover with LUNARAXE

Depending on directives from its command and control server, LUNEXSTEALER can install LUNARAXE, a malicious extension specifically designed for Chromium-based browsers. This extension masquerades as an innocuous office document editing tool while stealthily collecting cookies, browsing history, bookmarks, and credentials submitted through web forms.

LUNARAXE’s capabilities extend beyond mere data theft, mirroring advanced malicious browser backdoors that combine surveillance with remote control. Attackers gain the ability to manipulate browser tabs, capture screenshots, alter proxy settings, and execute arbitrary JavaScript on web pages. This grants them comprehensive visibility into a victim’s browsing activities and significant control over the content displayed. A PowerShell component named NAIVEMESS acts as a bridge, connecting the browser extension to the underlying Windows file system, allowing attackers to browse directories, read, write, and execute files. Additionally, another component of the extension actively removes website security policies that typically restrict scripts and data transfers.

Communication with its control server occurs over HTTP for the main malware, while the browser extension also supports WebSocket connections for remote interaction. For persistent access, LUNEXSTEALER can establish a scheduled task, psychedelicloveUtils, on infected systems, and the background browser component of LUNARAXE ensures it restarts automatically with the browser.

What You Should Do

CERT-UA emphasizes a critical distinction: legitimate human verification processes will never instruct users to open the Windows Run dialog, a command prompt, or PowerShell to paste and execute commands. Users encountering such suspicious instructions, even on seemingly trustworthy websites, should immediately close the page. Here are concrete, practical mitigation steps for defenders:

  • Educate Users: Train employees and users to recognize the red flags of fake verification pages. Emphasize that no legitimate CAPTCHA or security check requires executing commands.
  • Restrict User Privileges: Implement group policies to restrict ordinary users’ access to the Windows Run dialog and prevent the installation of MSI packages without administrator rights.
  • Monitor Installer Launches: Actively monitor for launches of msiexec.exe or other installer processes that contain URLs in their command lines, as this is a common indicator of compromise.
  • Enable Microsoft’s Vulnerable Driver Blocklist: Ensure that Microsoft’s vulnerable driver blocklist is enabled to prevent the exploitation of known flawed drivers like the AMD driver (CVE-2023-20598) used in this campaign.
  • Control Browser Extensions: Implement policies to permit only approved and vetted browser extensions. Regularly review and audit installed extensions across your organization’s endpoints.
  • Report Suspicious Activity: If you suspect encountering a fake verification page or compromise, report it to CERT-UA. Website owners or administrators who believe their sites have been compromised should also contact CERT-UA for assistance in identifying the intrusion vector and remediation.

Indicators of Compromise (IoCs):-

The following indicators have been identified in connection with this campaign. Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

<td style="text-align:left

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitHackerMalwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical Atlassian Jira RCE Exploit Released for CVE-2023-22524

Next Post

FBI Warns of Critical FortiBleed Attacks Exploiting Fortinet Firewalls and VPNs

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Rockstar Games Suffers Data Breach, GTA VI Source Code Stolen
October 7, 2026
Earth Sirrush Uses Notepad++ Plugins and Steganography for Espionage
October 7, 2026
Critical OpenAI Sandbox Flaw Exposed Paid AI Models
October 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us
Type Indicator Description
IPv4 107[.]175.82.242 Campaign infrastructure listed by CERT-UA.
IPv4 193[.]178.158.61 Campaign infrastructure.
IPv4 193[.]178.159.128 Host appearing in HTTP and remote-extension endpoints.
IPv4 109[.]238.86.112 Campaign infrastructure with a listed HTTP endpoint.
IPv4 109[.]238.86.113 Campaign infrastructure with a listed HTTP endpoint.
IPv4 176[.]53.159.40 Campaign infrastructure.
IPv4 159[.]69.234.218 Campaign infrastructure.
Domain ahahahahadebili[.]help Domain appearing in script and installer URLs.
Domain fsputnik[.]com Campaign domain.
Domain sputnk[.]com Domain appearing in an installer URL.
Domain uasputnik[.]com Domain appearing in multiple installer URLs.
Domain uasputn[.]com Domain appearing in an installer URL.
Domain partaonline[.]click Campaign domain.
Domain vibestglobal[.]com Campaign domain.
Domain flareru[.]live Campaign domain.
Domain plerdgate[.]com Campaign domain.
Domain ukrainerada[.]top Domain appearing in a script URL.
Domain radaukraine[.]top Campaign domain.
Domain astratechuthree[.]top Campaign domain.
Domain spectre.pp[.]ua Domain appearing in script and installer URLs.
Domain chillplace.pp[.]ua Campaign script endpoint.
Domain alohapages.pp[.]ua Campaign script endpoint.
Domain vatra.pp[.]ua Campaign domain.
Domain fainomedia.pp[.]ua Campaign domain.
Domain trembita.pp[.]ua Campaign domain.
Domain archivision.pp[.]ua Campaign domain.
WebSocket endpoint (ws)://193[.]178.159.128:8080/api/v1/ext/remote Remote-extension endpoint.
URL hXXp://107[.]175.82.242:9000/wilow/psychedeliclove[.]exe Executable download location.
URL hXXp://193[.]178.159.128:8080 Listed HTTP endpoint.
URL hXXps://uasputnik[.]com/elit.msi MSI download location.
URL hXXps://uasputnik[.]com/elita.msi MSI download location.
URL hXXps://uasputnik[.]com/elite.msi MSI download location.
URL hXXp://109[.]238.86.112:8080 Listed HTTP endpoint.
URL hXXp://109[.]238.86.113:8080 Listed HTTP endpoint.
URL hXXps://ahahahahadebili[.]help/tds/tds.php Campaign script endpoint.
URL hXXps://ahahahahadebili[.]help/think.msi MSI download location.
URL hXXps://sputnk[.]com/think.msi MSI download location.
URL hXXps://uasputn[.]com/esptnk.msi MSI download location.
URL hXXps://uasputnik[.]com/omen.msi MSI download location.
URL hXXps://ukrainerada[.]top/tds/tds.php Campaign script endpoint.
URL hXXps://chillplace.pp[.]ua/tds/tds.php Campaign script endpoint.
URL hXXps://alohapages.pp[.]ua/tds/tds.php Campaign script endpoint.
URL hXXps://spectre.pp[.]ua/tds/tds.php Campaign script endpoint.
URL hXXps://spectre.pp[.]ua/spectre.msi MSI download location.
URL https[:]//ilovecutecatetetes[.]click Additional URL listed by CERT-UA.
URL https[:]//ilovecutecatics[.]com Additional URL listed by CERT-UA.
URL fragment htt [ ]//il t ti [ ] [ ]8080 Final URL is clipped in the supplied PDF; this is its extracted fragment, not a usable or reconstructed indicator.
File PDFWKRNL.sys