As reported by SecurityAffairs, CERT-UA has uncovered a campaign affecting over 100 compromised websites that weaponize fake Cloudflare verification pages to deliver LunexStealer through ClickFix-style social engineering. While the ClickFix technique itself is well-established, several design choices in this campaign deserve closer attention from defenders and threat intelligence teams.
Blockchain as C2 Infrastructure Is the Real Story
The most significant operational detail here is not the lure or even the malware — it's the use of Polygon and Ethereum smart contracts as a configuration backbone. By storing the active domain, attack mode, and toggle state in an immutable, publicly readable contract, the operators have built a takedown-resistant command channel that traditional incident response cannot easily disrupt.
This matters because the standard playbook for disrupting stealer campaigns — reporting malicious domains to registrars, pursuing sinkholing, working with hosting providers — simply does not apply to a configuration value sitting in a smart contract. The blockchain becomes a read-only bulletin board that any compromised site can query, and no one can unilaterally edit. Expect this pattern to proliferate across additional malware families in the coming quarters.
The blockchain is being used not for payments or anonymity, but for availability. Attackers are treating public smart contracts as tamper-proof configuration endpoints that outlive infrastructure seizures.
Defense Evasion Chain Shows Maturity
The three MSI delivery variants described by CERT-UA reveal a threat group investing in operational redundancy. The second variant's use of CVE-2023-20598 — a known AMD driver vulnerability — as part of a BYOVD chain to disable Microsoft Defender before payload delivery is particularly notable. The third variant's pivot to DLL side-loading suggests the operators are actively rotating techniques to stay ahead of behavioral detection signatures.
| Variant | Delivery Method | Defense Evasion |
|---|---|---|
| Variant 1 | Direct MSI install of LunexStealer | Minimal |
| Variant 2 | MSI with UAC bypass + BYOVD (CVE-2023-20598) | Defender exception carving, driver-based tool blinding |
| Variant 3 | DLL side-loading via legitimate executable | Payload decryption at load time |
Who Is at Greatest Risk
Shield53 Recommendations
- Deploy driver blocklisting immediately. Enable Microsoft's vulnerable driver blocklist via WDAC or MEM. CVE-2023-20598 is a known quantity — there is no reason any modern Windows fleet should still permit loading of the affected AMD driver.
- Constrain PowerShell and MSI execution. Restrict
msiexecandpowershell.exeexecution for standard users via AppLocker or WDAC. The ClickFix chain depends on users pasting commands into an elevated prompt — break that dependency. - Monitor for smart contract reads. Detection of blockchain-configured C2 is emerging. Monitor outbound traffic to known RPC endpoints for Polygon and Ethereum (e.g.,
rpc.polygon-rpc.com, Infura, Alchemy) from web processes and unusual child processes. This is a behavioral indicator worth alerting on. - Train users on ClickFix specifically. Legitimate Cloudflare challenges never ask users to run commands. This single fact, communicated clearly, neutralizes the social engineering vector regardless of which domain the attackers rotate to next.
- Hunt for LunexStealer IOCs. Focus on post-exploitation behavior: outbound connections to unfamiliar domains from PowerShell or MSI child processes, credential store access patterns, and any Defender exclusion rules created outside of IT change windows.
This campaign is a preview of where stealer malware is heading: blockchain-resilient C2, multi-variant delivery to defeat single-mode detection, and browser-based social engineering that bypasses email entirely. Defenders who continue treating stealers as a lower-tier threat will find that the operational gap has closed significantly.