CERT-UA: UAC-0277 Hit 100+ Sites With Fake Cloudflare ClickFix Pages to Deliver LunexStealer, Including CVE-2023-20598 Loader
CERT-UA says unattributed cluster UAC-0277 compromised more than 100 websites with fake Cloudflare ClickFix pages to install LunexStealer, including a loader abusing AMD driver flaw CVE-2023-20598.
CERT-UA, tracking the unattributed activity as UAC-0277, reported that attackers compromised more than 100 websites in September 2026 — The Record says the sites were Ukrainian — by injecting JavaScript that displayed a fake Cloudflare verification page. Selected Windows visitors arriving from search results were prompted, via ClickFix, to run a PowerShell command that installed a remote MSI; The Hacker News says the lure was capped at twice in 12 hours and that EtherHiding pulled the delivery domain and mode from Polygon or Ethereum smart contracts, letting operators change domains or disable the lure remotely. The Hacker News describes three MSI variants: direct stealer installation; a loader that bypasses UAC, adds Microsoft Defender exclusions, and abuses vulnerable AMD driver PDFWKRNL.sys, which GBHackers, Security Affairs, and Cyber Security News tie to CVE-2023-20598; and DLL side-loading through FnHotkeyUtility.exe and spkvol.dll. Outlets spell the malware name differently — Lunex Stealer (The Record), LunexStealer (The Hacker News, Security Affairs), or LUNEXSTEALER (GBHackers, Cyber Security News) — and The Hacker News says it is also called Psychedelic Stealer. The Record, citing Ontinue, describes it as Russian-language malware-as-a-service that steals passwords, authentication tokens, and cryptocurrency wallets and can give remote access; Cyber Security News adds system information, and Security Affairs notes it can run executables, MSI packages, PowerShell, and raw commands. Some infections add the LUNARAXE Chromium extension — disguised as a Microsoft Word editor per The Record and Microsoft Office Word Editor per GBHackers and Security Affairs — which steals cookies, history, and form credentials, executes JavaScript, manipulates tabs, captures snapshots, and changes proxy settings, and may also deploy NAIVEMESS for PowerShell-based file-system access through a native-messaging host.
- CERT-UA tracks the unattributed campaign as UAC-0277; no group has been named.
- More than 100 websites were compromised in September 2026 with injected JavaScript showing fake Cloudflare checks; The Record says the sites were Ukrainian.
- ClickFix prompts told Windows visitors arriving from search results to run a PowerShell command that installed a remote MSI; The Hacker News says the lure was limited to twice in 12 hours.
- EtherHiding stored the delivery domain and mode in Polygon or Ethereum smart contracts, allowing operators to rotate domains or disable the lure remotely.
- Three MSI variants: direct stealer installation; a loader bypassing UAC, adding Microsoft Defender exclusions, and abusing AMD driver PDFWKRNL.sys (CVE-2023-20598); and DLL side-loading through FnHotkeyUtility.exe and spkvol.dll.
- The stealer takes passwords, tokens, cryptocurrency wallet data, and system information, can run executables, MSI packages, PowerShell, and raw commands, and The Record, citing Ontinue, calls it Russian-language malware-as-a-service.
- The LUNARAXE Chromium extension, disguised as a Word editor, steals cookies, history, and form credentials and can execute JavaScript, manipulate tabs, capture snapshots, and change proxy settings.
- NAIVEMESS provides PowerShell-based Windows file-system access through a native-messaging host.
Coverage timelineoldest first · each row is one article
- · 2d agoClickFix campaign in Ukraine compromises over 100 websites to spread Lunex malware
The Record· 71
A ClickFix campaign compromised over 100 Ukrainian websites to deliver the Lunex information stealer.
- · 1d ago100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer
The Hacker News· 78
CERT-UA says UAC-0277 used fake Cloudflare checks on over 100 sites to deliver LunexStealer.
- · 1d ago
Vulnerabilities in this storyAll →
- CVE-2023-205987.8<1%An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control over…published · amd radeon software
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-20598 | An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control over… An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control over arbitrary hardware ports or physical addresses resulting in a potential arbitrary code execution. |