LUNEXSTEALER Gives Hackers Remote Control of Browsers Through Malicious Chrome Extension
CERT-UA reports LUNEXSTEALER installs LUNARAXE for remote Chromium control after fake Cloudflare prompts.
CERT-UA tracks UAC-0277, a campaign using more than 100 compromised websites to distribute LUNEXSTEALER, a Windows infostealer. Fake Cloudflare checks tell Windows visitors to run a command that installs a malicious MSI, while delivery settings are read from Polygon or Ethereum smart contracts. The LUNARAXE extension, disguised as Microsoft Office Word Editor, can execute JavaScript, manipulate tabs, capture snapshots, change proxy settings, and steal cookies, history, and form credentials. Variants also bypass UAC, add Microsoft Defender exclusions, load vulnerable AMD driver PDFWKRNL.sys (CVE-2023-20598), DLL side-load through FnHotkeyUtility.exe, and may install NAIVEMESS for filesystem access.
- More than 100 sites deliver LUNEXSTEALER through fake Cloudflare checks.
- Polygon or Ethereum contracts supply the delivery domain and mode.
- LUNARAXE remotely controls Chromium browsers and steals credentials.
- One variant abuses AMD driver CVE-2023-20598 via BYOVD.
- NAIVEMESS gives PowerShell-based access to the Windows filesystem.
Vulnerabilities mentionedAll →
- CVE-2023-205987.8<1%An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control over…published · amd radeon software
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-20598 | An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control over… An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control over arbitrary hardware ports or physical addresses resulting in a potential arbitrary code execution. |
Full article626 words · extracted from gbhackers.com · click to collapse
A campaign that uses more than 100 compromised websites to distribute LUNEXSTEALER, a Windows infostealer that installs a browser extension giving attackers remote control.
The extension, LUNARAXE, masquerades as “Microsoft Office Word Editor” inside Chromium-based browsers.
Beyond stealing cookies, browsing history, and credentials entered into forms, it enables operators to execute JavaScript within webpages, manipulate tabs, capture snapshots, and change browser proxy settings.
An auxiliary component extends that access to the underlying Windows filesystem.
Attackers injected malicious JavaScript into legitimate websites, presenting visitors with counterfeit Cloudflare verification pages.
The pages instructed users to execute a command supposedly needed to confirm they were human.
Instead, the command downloaded and installed a malicious MSI package from an attacker-controlled server.
The injected script retrieves its delivery domain and operating mode from smart contracts on Polygon or Ethereum.
This blockchain-backed configuration lets operators centrally redirect the campaign without modifying every compromised website again.
CERT-UA described three modes: inactive, passive visitor tracking, and active delivery of the fake verification page.
Active delivery selectively targeted Windows visitors arriving through search engines, including Google, DuckDuckGo, meta.ua, and bigmir.net.
The fake challenge appeared no more than twice within 12 hours, limiting repeated exposure while filtering traffic for potential victims. Passive tracking collected the visited website and referring page information.
CERT-UA investigated three MSI variants. The first installed LUNEXSTEALER directly.
CERT-UA Researchers discovered that, the activity is tracked as UAC-0277 and combines ClickFix social engineering with multiple malware delivery techniques.
LUNEXSTEALER Hijacks Browsers
The second deployed a loader that attempted to bypass Windows User Account Control, added Microsoft Defender exclusions, and introduced the vulnerable AMD PDFWKRNL.sys driver before retrieving the stealer from a remote server.
That driver is affected by CVE-2023-20598, an improper privilege-management vulnerability permitting potentially dangerous access to hardware ports or physical addresses.
The campaign abuses it through bring-your-own-vulnerable-driver techniques. The third MSI variant uses DLL side-loading: legitimate FnHotkeyUtility.exe loads malicious spkvol.dll, which decrypts and launches LUNEXSTEALER.
The 64-bit payload steals browser passwords, tokens, cryptocurrency-wallet data, and system information. It also executes downloaded programs, MSI packages, PowerShell scripts, and command-shell instructions.
Server-provided configuration determines whether it deploys LUNARAXE, installs NAIVEMESS, or establishes persistence through the scheduled task “psychedelicloveUtils.” Its management traffic uses HTTP.
LUNARAXE.CORE handles command execution and data collection, communicating over HTTP and WebSocket.
LUNARAXE.STEALER intercepts login and password fields when users submit forms, forwarding captured values and page addresses internally.
LUNARAXE.STRIP removes Content Security Policy headers and corresponding HTML metadata, potentially weakening restrictions against injected scripts and unauthorized data transfers.
NAIVEMESS registers a PowerShell-based Native Messaging host named “com.lunex.explorer.”
Through this browser-to-native communication channel, attackers can enumerate drives, browse directories, read or overwrite files, and launch them. File transfers use Base64 chunks, with directories and grouped files archived as ZIP.
Commands arrive through the extension rather than an independent control channel.
CERT-UA recommends restricting the Windows Run dialog, controlling MSI installation, monitoring msiexec.exe commands containing URLs, enabling vulnerable-driver blocking, and enforcing browser-extension allowlists.
Its campaign advisory provides further context. Legitimate verification never requires executing commands; users should close such pages, while website owners should report suspected compromises promptly to CERT-UA.
IOCs
| Network | Host |
|---|---|
107[.]175.82.242 | %PROGRAMDATA%/SalmonLightSlateGray/FnHotkeyUtility.exe |
193[.]178.158.61 | %PROGRAMDATA%/SalmonLightSlateGray/spkvol.dll |
193[.]178.159.128 | %PROGRAMDATA%\SlateGrayChocolate\spkvol.dll |
109[.]238.86.112 | %PROGRAMDATA%\GrayLightCyan\FnHotkeyUtility.exe |
109[.]238.86.113 | %PROGRAMDATA%\GrayLightCyan\spkvol.dll |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.