UAC-0277 Campaign Uses ClickFix Technique to Deploy LUNEXSTEALER Malware
Threat actors identified as UAC-0277 are compromising legitimate websites to inject malicious JavaScript, tricking users into executing commands through fake Cloudflare verification pages. This ClickFix technique ultimately delivers MSI packages containing LUNEXSTEALER malware or additional loaders that use Bring Your Own Vulnerable Driver (BYOVD) tactics to evade security controls. The campaign also employs blockchain-based command-and-control infrastructure on Polygon and Ethereum to dynamically manage attacker resources.
CERT-UA has identified over 100 compromised websites and analyzed three MSI variants linked to the campaign. Researchers observed DLL side-loading involving FnHotkeyUtility.exe and exploitation of the vulnerable AMD PDFWKRNL.sys driver to bypass Windows Defender protections. The investigation also uncovered the LUNARAXE browser extension and the NAIVEMESS PowerShell component, which are used to collect and exfiltrate data.
To mitigate the risk, administrators are advised to restrict access to the Run dialog through Group Policy and limit MSI installation privileges to authorized users. Enabling the Microsoft Vulnerable Driver Blocklist is crucial for reducing the risk of BYOVD attacks. Organizations should also enforce browser extension allowlists and monitor suspicious msiexec.exe command-line activity involving remote URLs.
In response to detected threats, organizations should isolate affected hosts and terminate processes associated with LUNEXSTEALER. Reviewing scheduled tasks for entries named psychedelicloveUtils and inspecting browser profiles for the Microsoft Office Word Editor extension are recommended actions. Any identified fake Cloudflare verification pages should be reported to CERT-UA.