As reported by SecurityAffairs, CERT-UA has uncovered a campaign affecting over 100 compromised websites that weaponize fake Cloudflare verification pages to deliver LunexStealer through ClickFix-style social engineering. While the ClickFix technique itself is well-established, several design choices in this campaign deserve closer attention from defenders and threat intelligence teams.

Threat Alert: As reported by SecurityAffairs, CERT-UA has uncovered a campaign affecting over 100 compromised websites that weaponize fake Cloudflare verification pages to deliver LunexStealer through ClickFix-style social engineering.

Blockchain as C2 Infrastructure Is the Real Story

The most significant operational detail here is not the lure or even the malware — it's the use of Polygon and Ethereum smart contracts as a configuration backbone. By storing the active domain, attack mode, and toggle state in an immutable, publicly readable contract, the operators have built a takedown-resistant command channel that traditional incident response cannot easily disrupt.

This matters because the standard playbook for disrupting stealer campaigns — reporting malicious domains to registrars, pursuing sinkholing, working with hosting providers — simply does not apply to a configuration value sitting in a smart contract. The blockchain becomes a read-only bulletin board that any compromised site can query, and no one can unilaterally edit. Expect this pattern to proliferate across additional malware families in the coming quarters.

The blockchain is being used not for payments or anonymity, but for availability. Attackers are treating public smart contracts as tamper-proof configuration endpoints that outlive infrastructure seizures.

Defense Evasion Chain Shows Maturity

The three MSI delivery variants described by CERT-UA reveal a threat group investing in operational redundancy. The second variant's use of CVE-2023-20598 — a known AMD driver vulnerability — as part of a BYOVD chain to disable Microsoft Defender before payload delivery is particularly notable. The third variant's pivot to DLL side-loading suggests the operators are actively rotating techniques to stay ahead of behavioral detection signatures.

VariantDelivery MethodDefense Evasion
Variant 1Direct MSI install of LunexStealerMinimal
Variant 2MSI with UAC bypass + BYOVD (CVE-2023-20598)Defender exception carving, driver-based tool blinding
Variant 3DLL side-loading via legitimate executablePayload decryption at load time

Who Is at Greatest Risk

Defense Evasion Chain Shows Maturity
Windows endpoints arriving via search engines: The campaign specifically targets Windows users with search-engine referrer headers, meaning organic web traffic — not targeted spear-phishing — is the infection vector.
Organizations without driver blocklisting: The BYOVD variant relies on loading a vulnerable signed AMD driver. Environments that permit third-party driver loading are fully exposed.
Teams relying on domain-based detections: Because the active domain rotates via smart contract updates, static blocklists will always lag behind the operator's next configuration push.

Shield53 Recommendations

  • Deploy driver blocklisting immediately. Enable Microsoft's vulnerable driver blocklist via WDAC or MEM. CVE-2023-20598 is a known quantity — there is no reason any modern Windows fleet should still permit loading of the affected AMD driver.
  • Constrain PowerShell and MSI execution. Restrict msiexec and powershell.exe execution for standard users via AppLocker or WDAC. The ClickFix chain depends on users pasting commands into an elevated prompt — break that dependency.
  • Monitor for smart contract reads. Detection of blockchain-configured C2 is emerging. Monitor outbound traffic to known RPC endpoints for Polygon and Ethereum (e.g., rpc.polygon-rpc.com, Infura, Alchemy) from web processes and unusual child processes. This is a behavioral indicator worth alerting on.
  • Train users on ClickFix specifically. Legitimate Cloudflare challenges never ask users to run commands. This single fact, communicated clearly, neutralizes the social engineering vector regardless of which domain the attackers rotate to next.
  • Hunt for LunexStealer IOCs. Focus on post-exploitation behavior: outbound connections to unfamiliar domains from PowerShell or MSI child processes, credential store access patterns, and any Defender exclusion rules created outside of IT change windows.

This campaign is a preview of where stealer malware is heading: blockchain-resilient C2, multi-variant delivery to defeat single-mode detection, and browser-based social engineering that bypasses email entirely. Defenders who continue treating stealers as a lower-tier threat will find that the operational gap has closed significantly.