As reported by The Hacker News, CERT-UA has disclosed a sprawling credential theft campaign attributed to threat cluster UAC-0277, involving over 100 compromised websites injected with malicious JavaScript designed to distribute LunexStealer (also tracked as Psychedelic Stealer). What sets this campaign apart is not the stealer itself, but the layered delivery architecture that combines three increasingly prevalent evasion techniques into a single, resilient kill chain.
The Convergence Problem
The campaign operationalizes three techniques that defenders have been observing in isolation throughout 2025-2026, but their combination creates detection friction that most security stacks are not calibrated for:
- ClickFix social engineering — abusing user familiarity with Cloudflare's human verification prompt to coerce execution of attacker-supplied commands. This bypasses traditional drive-by exploit defenses because the user voluntarily initiates the payload.
- EtherHiding — retrieving C2 configuration and payload domains from smart contracts on Polygon or Ethereum. This eliminates static domains from the kill chain and makes infrastructure takedowns exceptionally difficult, as blockchain state cannot be trivially revoked.
- Multi-variant MSI delivery — three distinct package variants ensure redundancy and complicate signature-based detection. Variant 2's use of the vulnerable AMD driver (
PDFWKRNL.sys) for bring-your-own-vulnerable-driver (BYOVD) defense evasion is particularly notable.
Why This Matters Beyond the Headline Count
The 100-website figure is almost certainly an undercount. CERT-UA's telemetry reflects Ukrainian observation, but the injected JavaScript and blockchain-stored configuration are globally reachable. The smart contract's Mode 0/1/2 state machine means operators can toggle the campaign dormant at will, making it trivial to evade snapshot-based scanning by security researchers or law enforcement. Mode 1's passive tracking — quietly harvesting referrer data — also means the attacker gains intelligence value even from visitors who never receive the payload.
The campaign's conditional logic — only targeting Windows users arriving from search engines, capping exposure to twice per 12 hours — demonstrates operational discipline designed to minimize detection by automated crawlers and repeat-visitor reporting.
The Browser Extension Problem
LunexStealer's deployment of the LUNARAXE browser extension, masquerading as Microsoft Office Word Editor, significantly expands the blast radius beyond credential exfiltration. Remote browser control and arbitrary JavaScript execution capability transforms the victim's authenticated browser session into a live attack platform — enabling session token theft, real-time transaction manipulation, and lateral movement into SaaS applications that may lack MFA enforcement on established sessions.
Shield53 Recommendations
- Block execution of MSI from remote/internet zones — Enforce AppLocker or WDAC policies restricting MSI installation to signed, locally-verified packages. The ClickFix vector fundamentally depends on users executing MSI from remote URLs.
- Detect EtherHinding infrastructure — Deploy egress monitoring for Polygon RPC endpoints and Ethereum node traffic from non-developer workstations. Legitimate enterprise use of these networks is rare outside blockchain engineering teams.
- Hunt for BYOVD indicators — Monitor for
PDFWKRNL.sysloading outside standard AMD driver installation paths. Consider blocklisting this known-vulnerable driver via vulnerable driver blocklist enforcement. - Browser extension governance — Enforce extension allowlisting via GPO/MDM. Block installation of extensions with names matching Microsoft Office Word Editor or similar impersonation patterns.
- DLL sideloading detection — Variant 3's use of
FnHotkeyUtility.exeloadingspkvol.dllis detectable via monitoring for unsigned DLLs loaded by signed, legitimate executables in non-standard paths. - User awareness reinforcement — Communicate that Cloudflare's real verification never requires executing commands or installing software. This specific social engineering pattern should be highlighted in current awareness training.
- Session token monitoring — Given LUNARAXE's capabilities, monitor for anomalous activity on established authenticated sessions, particularly within SaaS and financial applications.
For organizations maintaining their own websites, this campaign underscores the importance of integrity monitoring for served JavaScript — the compromise chain begins with site injection, and CSP deployment with subresource integrity (SRI) enforcement can detect or prevent the initial payload stage. The blockchain C2 layer may be novel, but the entry point remains traditional web compromise — and that is where defensive investment yields the highest return.