LUNEXSTEALER Gives Hackers Remote Control of Browsers Through Malicious Chrome Extension
CERT-UA reports LUNEXSTEALER installs LUNARAXE for remote Chromium control after fake Cloudflare prompts.
CERT-UA tracks UAC-0277, a campaign using more than 100 compromised websites to distribute LUNEXSTEALER, a Windows infostealer. Fake Cloudflare checks tell Windows visitors to run a command that installs a malicious MSI, while delivery settings are read from Polygon or Ethereum smart contracts. The LUNARAXE extension, disguised as Microsoft Office Word Editor, can execute JavaScript, manipulate tabs, capture snapshots, change proxy settings, and steal cookies, history, and form credentials. Variants also bypass UAC, add Microsoft Defender exclusions, load vulnerable AMD driver PDFWKRNL.sys (CVE-2023-20598), DLL side-load through FnHotkeyUtility.exe, and may install NAIVEMESS for filesystem access.