Computer Emergency Response Team of Ukraine (CERT-UA) has identified a large scale cyber campaign involving more than 100 compromised websites that have been modified to distribute the information stealing malware known as LunexStealer, also referred to as Psychedelic Stealer. According to the agency, the activity was observed during September 2026 and has been attributed to a threat cluster tracked as UAC-0277. While CERT-UA did not disclose the identities of affected organisations or confirm whether any systems were successfully compromised, it warned that the campaign relies on deceptive verification pages designed to trick users into downloading malicious software. The advisory highlights the continued use of social engineering tactics that imitate trusted online services to increase the likelihood of user interaction.
CERT-UA reported that visitors to compromised websites are presented with a fraudulent Cloudflare verification page claiming to confirm that the visitor is human. Instead of performing a legitimate verification process, the page instructs users to execute a command that downloads and installs a malicious MSI package from a remote server using a technique commonly known as ClickFix. Researchers also found that the attackers use the EtherHiding technique, retrieving configuration information from smart contracts hosted on Polygon or Ethereum blockchain networks to determine how the malicious script should behave. Depending on its operating mode, the script can remain inactive, silently collect information about website visitors or display the fake verification page. CERT-UA noted that the malicious verification page is shown only to Windows users arriving through search engine results and is designed to limit repeated displays within a twelve hour period, reducing the likelihood of detection while increasing the effectiveness of the campaign.
The agency identified multiple variants of the malicious MSI packages used during the operation. One variant installs LunexStealer directly on compromised systems, while another attempts to weaken security protections before retrieving the malware from a remote server. A third variation launches the stealer by abusing legitimate software components through DLL sideloading techniques. CERT-UA also noted that LunexStealer is capable of deploying a malicious browser extension known as LUNARAXE, which disguises itself as a Microsoft Office related extension. According to previous research from Arctic Wolf Labs and Ontinue, the extension is designed to collect browser cookies, browsing history and credentials entered into web forms while also enabling remote browser control and execution of malicious scripts. Researchers further identified an auxiliary component called NAIVEMESS that can provide broader access to files stored on Windows systems when instructed through the malware’s command infrastructure, increasing the overall impact of successful infections.
To reduce the risk posed by this campaign, CERT-UA has advised organisations to restrict access to the Windows Run dialog through Group Policy, prevent non administrative users from installing MSI packages and closely monitor systems for suspicious use of the Windows Installer process. The agency also recommended enabling Microsoft vulnerable driver protections, restricting browser extension installation to approved software and strengthening endpoint monitoring for unusual activity. Microsoft has similarly advised organisations to enable its Attack Surface Reduction rule that blocks abuse of vulnerable signed drivers, helping prevent attackers from using trusted drivers to disable security tools. Security experts encourage organisations to deploy these protective measures promptly while educating users to avoid interacting with unexpected verification prompts or executing commands requested by unfamiliar websites, particularly when visiting pages reached through internet search results.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.