Essential Insights
- Over 100 Ukrainian websites infected with malicious JavaScript serve LunexStealer, a malware that exfiltrates browser data and credentials through fake verification pages.
- The malware is delivered via MSI packages using techniques like UAC bypass, Defender exclusions, DLL sideloading, and remote execution, targeting Windows users from search engine results.
- LunexStealer installs a malicious browser extension (LUNARAXE) and auxiliary tools (NAIVEMESS) to manipulate files, steal cookies, and execute remote commands, risking extensive data breach and system control.
The Threat, Techniques, and Targets
CERT-UA reports that over 100 websites have been compromised with malicious JavaScript to distribute LunexStealer, an information-stealing malware. The activity was noticed in September 2026 and is linked to the threat group UAC-0277. The attackers use a fake Cloudflare verification page to trick visitors. When users visit the infected sites, they see a page that asks them to run a command. This command downloads and installs malware from a remote server.
The attack makes use of the EtherHiding technique, which helps hide the true domain and script mode from detection. There are three operating modes: inactive, passive tracking, and fake verification display. In mode 2, Windows users arriving from search engine results are shown the fake page only twice in 12 hours. These fake pages lure users to download MSI packages. These packages deliver LunexStealer and come in three variants. The variants include installing the stealer directly, bypassing UAC, or using DLL sideloading to run the malware on the system.
LunexStealer is designed to steal information and install a malicious browser extension called LUNARAXE. The extension pretends to be a Microsoft Word program and can steal cookies, browsing history, and credentials. It also allows remote control of the browser. Alongside the extension, LunexStealer uses a component called NAIVEMESS to access the Windows file system. This allows the malware to browse, read, write, and execute files on the victim’s system.
Impact, Security, and Guidance
This attack can lead to serious security issues. The malware steals sensitive data from infected systems. The malicious MSI packages and later modules can bypass security controls such as UAC and Defender. The use of browser extensions and file system access increases the risk of data theft and system compromise.
Organizations must take steps to reduce threat exposure. They should prevent regular users from using the Windows Run dialog and limit the installation of MSI packages. Monitoring for the execution of “msiexec.exe” is important. Blocking vulnerable drivers and restricting browser extensions to trusted ones can also help. Microsoft recommends enabling the Attack Surface Reduction rule for signed driver abuse prevention.
Because specific remediation instructions are not provided, organizations should contact their security vendors or authorities for detailed guidance. It is vital to follow their advice to protect systems from this threat.
Continue Your Tech Journey
Stay informed on the revolutionary breakthroughs in Quantum Computing research.
Explore past and present digital transformations on the Internet Archive.
ThreatIntel-V1
