CERT-UA: Fake Cloudflare Checks Deliver LunexStealer Malware
CERT-UA: Fake Cloudflare Checks Deliver LunexStealer MalwareOve 2026-10-7 13:22:17 Author: securityaffairs.com(查看原文) 阅读量:6 收藏

CERT-UA: Fake Cloudflare Checks Deliver LunexStealer Malware

Over 100 hacked websites used fake Cloudflare checks to trick visitors into installing LunexStealer through ClickFix commands.

The lure is the now-familiar ClickFix technique, dressed up as Cloudflare’s standard bot check. The fake page asks you to run a command, supposedly to confirm you’re not a bot, and that command quietly downloads and installs an MSI package from an attacker-controlled server. There’s no bot to fool here, you’re the one being fooled.

“In September 2026, CERT-UA specialists discovered over 100 compromised websites to which malicious JavaScript code had been added by attackers. When visiting such a site, the user was shown a fake Cloudflare verification page, which, under the pretext of confirming that the visitor was a human, offered to execute a command.” reads the report published by the Ukraine CERT-UA. “Executing the command resulted in downloading and installing an MSI package from a remote server (ClickFix technique).”

What makes this campaign interesting is how the attackers control it. The domain used for the fake page and the script’s settings are stored in a smart contract on the Polygon or Ethereum blockchain. The script checks the contract each time it runs, so the attackers can change the domain or turn the attack on and off without changing the compromised websites. In effect, they are using the blockchain as a remote control that is difficult to take down.

The script has three modes: off, silent visitor tracking, and the full fake verification page. The attack mode only targets Windows users who arrive through search engines, and it will show the fake page no more than twice within 12 hours for the same visitor. This is clearly designed to keep the campaign quiet and make it harder to spot through unusual traffic patterns.

CERT-UA pulled apart three separate MSI variants used in the campaign. The first just installs the stealer directly. The second is more elaborate, trying to slip past Windows User Account Control, carving out Microsoft Defender exceptions, and deploying a vulnerable AMD driver to exploit CVE-2023-20598, a bring-your-own-vulnerable-driver (BYOVD) move that blinds security tools before the real payload drops.

The third variant skips the driver abuse entirely and uses DLL side-loading instead, tricking a legitimate executable into loading a malicious library that decrypts and launches the stealer. Three different paths, the same room goal. CERT-UA names that payload LunexStealer.

LunexStealer isn’t just a credential grabber, it doubles as a remote execution tool, able to download and run executables, MSI packages, PowerShell scripts, and raw commands on demand. Depending on what configuration it pulls from its command server, it can also install a browser extension called LUNARAXE, disguised under the name “Microsoft Office Word Editor” so it blends into a list of legitimate-looking add-ons.

That extension steals cookies, browsing history, and anything typed into a web form, and gives the attacker live remote control over the browser itself.

“Depending on the configuration received from the control server, LUNEXSTEALER can install a malicious browser extension called LUNARAXE, which appears in the browser under the name “Microsoft Office Word Editor”.” continues the report. “The extension steals cookies, browsing history, and credentials entered into web forms, and also allows attackers to remotely control the browser: execute JavaScript code on web pages, manage tabs and take snapshots of them, and change proxy server settings. If the NAIVEMESS auxiliary component is present, the extension also gains access to the computer’s file system.”

There’s a file system access layer too, a PowerShell component called NAIVEMESS that CERT-UA says registers itself as a legitimate browser-to-system messaging host, letting the extension read, write, and launch files on the victim’s machine.

CERT-UA’s advice is simple: a real security check will never ask you to open the Run window, Command Prompt, or PowerShell and paste a command. If a website asks you to do that, close it, even if the site looks familiar.

For system administrators, CERT-UA recommends additional controls, such as restricting Win+R with Group Policy, limiting who can install MSI files, and blocking known vulnerable drivers.

Full CERT-UA advisory with indicators of compromise and the complete malware breakdown is available here.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, LunexStealer)




文章来源: https://securityaffairs.com/200537/hacking/cert-ua-fake-cloudflare-checks-deliver-lunexstealer-malware.html
如有侵权请联系:admin#unsafe.sh