Fake Cloudflare CAPTCHAs Spread LUNEXSTEALER to 100+ Websites
Key Takeaways Over 100 websites were compromised to distribute LUNEXSTEALER, a Windows information-stealing malware. The attack leverages fake Cloudflare CAPTCHA pages, prompting users to execute a...
Key Takeaways
- Over 100 websites were compromised to distribute LUNEXSTEALER, a Windows information-stealing malware.
- The attack leverages fake Cloudflare CAPTCHA pages, prompting users to execute a command to bypass the “security check.”
- LUNEXSTEALER collects sensitive data like browser passwords, crypto wallet information, and system details, and can install a malicious browser extension, LUNARAXE.
- The campaign, identified as UAC-0277 by CERT-UA, employs sophisticated techniques, including exploiting a vulnerable AMD driver (CVE-2023-20598) and using blockchain smart contracts for command and control.
- Users should be highly suspicious of any CAPTCHA or security prompt that requires executing commands in the Windows Run dialog, command prompt, or PowerShell.
Cybercriminals have successfully breached more than 100 websites, deploying deceptive Cloudflare verification pages to disseminate LUNEXSTEALER, a potent Windows-based information-stealing malware. This widespread campaign transforms routine website visits into opportunities for system compromise, as detailed in a recent report.
Table Of Content
The attackers injected malicious JavaScript into legitimate website pages. This script then presented a convincing, yet fake, Cloudflare security challenge. Unlike typical CAPTCHAs, this fraudulent prompt instructed users to execute a specific command to “verify” their humanity, a tactic designed to bypass traditional security awareness against suspicious downloads. This method, often referred to as ClickFix, manipulates users into initiating the infection themselves, rather than relying on them to open an obvious attachment.
CERT-UA researchers, who began tracking this activity as UAC-0277 in September 2026, analyzed three distinct installer variants used to deliver the LUNEXSTEALER malware. Their report shared with Cyber Security News (CSN) on September 30, 2026, highlighted the malware’s extensive capabilities.
LUNEXSTEALER’s Capabilities and Evasion Techniques
LUNEXSTEALER is designed to harvest a wide array of sensitive data, including saved browser passwords, authentication tokens, cryptocurrency wallet data, and detailed system information. Its remote execution features further escalate the threat, enabling attackers to download and install additional software and issue arbitrary commands on compromised systems. The full extent of victim compromise remains undetermined by the advisory.
The malicious script’s operational parameters and verification domain were dynamically retrieved from a smart contract hosted on either the Polygon or Ethereum blockchain networks. This innovative command-and-control mechanism allows the attackers to centrally modify the campaign’s behavior and target domains without needing to individually update the code on each compromised website.
The campaign operates in three modes: inactive, passive visitor tracking, and active fake verification display. In passive mode, the script gathers information about the compromised website and the referring page, sending it to the attacker’s infrastructure. The active mode, however, is where the deceptive CAPTCHA challenge is presented to the user.
This fake verification page was selectively displayed. It targeted only Windows users who arrived at the compromised sites via search engines such as Google and DuckDuckGo. To avoid detection and maintain stealth, the prompt appeared a maximum of twice within a 12-hour period, ensuring a measured and less aggressive exposure to potential victims.
One of the identified installer variants directly deployed LUNEXSTEALER. Another employed a loader designed to bypass Windows User Account Control (UAC), establish exclusions within Microsoft Defender, and exploit CVE-2023-20598 in a vulnerable AMD driver (PDFWKRNL.sys version 0.0.0.1) to interfere with security tools. This tactic of abusing legitimate but flawed drivers has been observed in other sophisticated attacks seeking to undermine system defenses. A third installer variant utilized a legitimate executable, FnHotkeyUtility.exe, to side-load a malicious library, spkvol.dll, which then decrypted and launched the stealer component.
Browser Takeover with LUNARAXE
Depending on directives from its command and control server, LUNEXSTEALER can install LUNARAXE, a malicious extension specifically designed for Chromium-based browsers. This extension masquerades as an innocuous office document editing tool while stealthily collecting cookies, browsing history, bookmarks, and credentials submitted through web forms.
LUNARAXE’s capabilities extend beyond mere data theft, mirroring advanced malicious browser backdoors that combine surveillance with remote control. Attackers gain the ability to manipulate browser tabs, capture screenshots, alter proxy settings, and execute arbitrary JavaScript on web pages. This grants them comprehensive visibility into a victim’s browsing activities and significant control over the content displayed. A PowerShell component named NAIVEMESS acts as a bridge, connecting the browser extension to the underlying Windows file system, allowing attackers to browse directories, read, write, and execute files. Additionally, another component of the extension actively removes website security policies that typically restrict scripts and data transfers.
Communication with its control server occurs over HTTP for the main malware, while the browser extension also supports WebSocket connections for remote interaction. For persistent access, LUNEXSTEALER can establish a scheduled task, psychedelicloveUtils, on infected systems, and the background browser component of LUNARAXE ensures it restarts automatically with the browser.
What You Should Do
CERT-UA emphasizes a critical distinction: legitimate human verification processes will never instruct users to open the Windows Run dialog, a command prompt, or PowerShell to paste and execute commands. Users encountering such suspicious instructions, even on seemingly trustworthy websites, should immediately close the page. Here are concrete, practical mitigation steps for defenders:
- Educate Users: Train employees and users to recognize the red flags of fake verification pages. Emphasize that no legitimate CAPTCHA or security check requires executing commands.
- Restrict User Privileges: Implement group policies to restrict ordinary users’ access to the Windows Run dialog and prevent the installation of MSI packages without administrator rights.
- Monitor Installer Launches: Actively monitor for launches of
msiexec.exeor other installer processes that contain URLs in their command lines, as this is a common indicator of compromise. - Enable Microsoft’s Vulnerable Driver Blocklist: Ensure that Microsoft’s vulnerable driver blocklist is enabled to prevent the exploitation of known flawed drivers like the AMD driver (CVE-2023-20598) used in this campaign.
- Control Browser Extensions: Implement policies to permit only approved and vetted browser extensions. Regularly review and audit installed extensions across your organization’s endpoints.
- Report Suspicious Activity: If you suspect encountering a fake verification page or compromise, report it to CERT-UA. Website owners or administrators who believe their sites have been compromised should also contact CERT-UA for assistance in identifying the intrusion vector and remediation.
Indicators of Compromise (IoCs):-
The following indicators have been identified in connection with this campaign. Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
| Type | Indicator | Description |
|---|---|---|
| IPv4 | 107[.]175.82.242 |
Campaign infrastructure listed by CERT-UA. |
| IPv4 | 193[.]178.158.61 |
Campaign infrastructure. |
| IPv4 | 193[.]178.159.128 |
Host appearing in HTTP and remote-extension endpoints. |
| IPv4 | 109[.]238.86.112 |
Campaign infrastructure with a listed HTTP endpoint. |
| IPv4 | 109[.]238.86.113 |
Campaign infrastructure with a listed HTTP endpoint. |
| IPv4 | 176[.]53.159.40 |
Campaign infrastructure. |
| IPv4 | 159[.]69.234.218 |
Campaign infrastructure. |
| Domain | ahahahahadebili[.]help |
Domain appearing in script and installer URLs. |
| Domain | fsputnik[.]com |
Campaign domain. |
| Domain | sputnk[.]com |
Domain appearing in an installer URL. |
| Domain | uasputnik[.]com |
Domain appearing in multiple installer URLs. |
| Domain | uasputn[.]com |
Domain appearing in an installer URL. |
| Domain | partaonline[.]click |
Campaign domain. |
| Domain | vibestglobal[.]com |
Campaign domain. |
| Domain | flareru[.]live |
Campaign domain. |
| Domain | plerdgate[.]com |
Campaign domain. |
| Domain | ukrainerada[.]top |
Domain appearing in a script URL. |
| Domain | radaukraine[.]top |
Campaign domain. |
| Domain | astratechuthree[.]top |
Campaign domain. |
| Domain | spectre.pp[.]ua |
Domain appearing in script and installer URLs. |
| Domain | chillplace.pp[.]ua |
Campaign script endpoint. |
| Domain | alohapages.pp[.]ua |
Campaign script endpoint. |
| Domain | vatra.pp[.]ua |
Campaign domain. |
| Domain | fainomedia.pp[.]ua |
Campaign domain. |
| Domain | trembita.pp[.]ua |
Campaign domain. |
| Domain | archivision.pp[.]ua |
Campaign domain. |
| WebSocket endpoint | (ws)://193[.]178.159.128:8080/api/v1/ext/remote |
Remote-extension endpoint. |
| URL | hXXp://107[.]175.82.242:9000/wilow/psychedeliclove[.]exe |
Executable download location. |
| URL | hXXp://193[.]178.159.128:8080 |
Listed HTTP endpoint. |
| URL | hXXps://uasputnik[.]com/elit.msi |
MSI download location. |
| URL | hXXps://uasputnik[.]com/elita.msi |
MSI download location. |
| URL | hXXps://uasputnik[.]com/elite.msi |
MSI download location. |
| URL | hXXp://109[.]238.86.112:8080 |
Listed HTTP endpoint. |
| URL | hXXp://109[.]238.86.113:8080 |
Listed HTTP endpoint. |
| URL | hXXps://ahahahahadebili[.]help/tds/tds.php |
Campaign script endpoint. |
| URL | hXXps://ahahahahadebili[.]help/think.msi |
MSI download location. |
| URL | hXXps://sputnk[.]com/think.msi |
MSI download location. |
| URL | hXXps://uasputn[.]com/esptnk.msi |
MSI download location. |
| URL | hXXps://uasputnik[.]com/omen.msi |
MSI download location. |
| URL | hXXps://ukrainerada[.]top/tds/tds.php |
Campaign script endpoint. |
| URL | hXXps://chillplace.pp[.]ua/tds/tds.php |
Campaign script endpoint. |
| URL | hXXps://alohapages.pp[.]ua/tds/tds.php |
Campaign script endpoint. |
| URL | hXXps://spectre.pp[.]ua/tds/tds.php |
Campaign script endpoint. |
| URL | hXXps://spectre.pp[.]ua/spectre.msi |
MSI download location. |
| URL | https[:]//ilovecutecatetetes[.]click |
Additional URL listed by CERT-UA. |
| URL | https[:]//ilovecutecatics[.]com |
Additional URL listed by CERT-UA. |
| URL fragment | htt [ ]//il t ti [ ] [ ]8080 |
Final URL is clipped in the supplied PDF; this is its extracted fragment, not a usable or reconstructed indicator. |
| File | PDFWKRNL.sys |



No Comment! Be the first one.