Yaamlabs

Phishing

LunexStealer: blockchain-steered fake Cloudflare checks

CERT-UA found 100+ hacked sites serving fake Cloudflare checks run from a smart contract, ending in LunexStealer, a rogue extension and an AMD driver.

Ukraine's computer emergency response team, CERT-UA, published a report on September 30 about more than 100 legitimate websites that had been altered to show visitors a fake Cloudflare "I am not a robot" check. The check asks the visitor to run a command, which installs an MSI package carrying LunexStealer, also sold as Psychedelic Stealer. CERT-UA tracks the activity as UAC-0277, has not tied it to a known group, and has not said how many computers were infected. English-language coverage followed on October 7.

The lure itself is ordinary ClickFix. The parts behind it are less common: the compromised sites take their orders from a blockchain smart contract, one installer brings a vulnerable AMD driver to blind endpoint protection, and the stealer can leave behind a browser extension and a native messaging host that keep attackers in the machine after the stealer binary is gone. Any Windows fleet whose users browse to small, trusted websites from a search engine is in scope.

How the smart contract steers 100 websites

The script injected into each site does not carry a hard-coded lure address. Each time it runs it reads a smart contract on the Polygon or Ethereum blockchain, which stores the domain that serves the fake check and a mode setting. Mode 0 leaves the site alone, mode 1 quietly records the site and the page the visitor came from, and mode 2 shows the fake verification page. The technique is known as EtherHiding.

For the operators, that means one blockchain transaction changes the lure domain or switches the whole campaign on or off across every compromised site, with no need to log back into any of them. Taking down a lure domain does not break the chain either, because the next value written to the contract replaces it. Blocking Polygon or Ethereum endpoints is not a realistic fix: both are public networks with legitimate traffic, and the blocklists built from CERT-UA's report list only the attacker-registered domains.

The script also filters who sees the page. In mode 2 it targets Windows visitors arriving from a search engine and shows the check no more than twice in 12 hours to the same visitor. That throttle makes the injection harder to spot in traffic data, and a site owner who loads their own homepage directly sees nothing. CERT-UA's examples include an online shop and a site of colouring pages for children.

Three installers, one with a kernel driver

CERT-UA analysed three MSI variants. The first installs LunexStealer directly. The third uses DLL side-loading, where a legitimate program is made to load a malicious library that decrypts and starts the stealer.

The second variant is the one to plan for. Its loader tries to bypass User Account Control (UAC), adds Microsoft Defender exclusions so the payload folder is never scanned, and installs AMD's PDFWKRNL.sys driver, a component of AMD Radeon software affected by CVE-2023-20598. That flaw is an improper privilege management bug: the driver lets the code that calls it read and write kernel memory. This is bring your own vulnerable driver (BYOVD): the driver is signed, so Windows loads it, and the attacker uses it as a kernel-level tool.

Ontinue's analysis of the Lunex loader, published on September 24, explains what the driver is used for. Instead of killing security processes, the loader zeroes the kernel callbacks that endpoint detection and response (EDR) products register to hear about new processes and other events. The EDR agent keeps running and looks healthy on the console, but it stops receiving those events. Ontinue also found that Hypervisor-protected Code Integrity (HVCI) and the Microsoft Vulnerable Driver Blocklist, as they stood at the time of testing, did not stop the PDFWKRNL.sys variant used in this chain from loading.

The extension and the native messaging host

LunexStealer itself goes after saved passwords, cookies, session and authentication tokens, cryptocurrency wallets and system information in seven Chromium browsers: Chrome, Edge, Brave, Yandex Browser, Opera, Opera GX and Vivaldi. Ontinue counted 28 Lunex control panels in 13 countries, which fits a malware-as-a-service platform rented to several operators.

Depending on the configuration it receives from its control server, the stealer also installs LUNARAXE, a Chromium extension that shows up as "Microsoft Office Word Editor". It steals cookies, history and credentials typed into web forms, runs JavaScript on pages the attackers choose, changes the browser's proxy settings and strips Content Security Policy headers, the response headers that normally stop injected scripts from running.

An extension cannot touch the file system on its own. Chromium allows it to talk to a local program through native messaging: a registry key names a host, the key points to a JSON manifest, and the manifest lists the program to start and which extension IDs may call it. NAIVEMESS registers a PowerShell host called com.lunex.explorer. CERT-UA says it can list drives, browse folders, read, create and overwrite files, and run them. Because that access comes through the browser, deleting the stealer executable leaves the attacker with a working file manager and launcher on the machine.

What to do

Check endpoints now

  • Look for com.lunex.explorer under HKCU\Software\Google\Chrome\NativeMessagingHosts and HKCU\Software\Microsoft\Edge\NativeMessagingHosts, and the matching HKLM\Software paths. Any host key nobody can explain deserves a look, since the manifest it points to names the program the browser will start.
  • Search your browser management reports for an extension called "Microsoft Office Word Editor".
  • Run Get-MpPreference | Select ExclusionPath, ExclusionProcess across the fleet and compare the results with the exclusions you set centrally. Defender logs configuration changes as event ID 5007 in Microsoft-Windows-Windows Defender/Operational.
  • Hunt for PDFWKRNL.sys on machines without AMD Radeon software, and for new kernel driver services in the System log (event ID 7045) or Sysmon driver loads (event ID 6).

For the indicators themselves, use the domain and hash lists in CERT-UA's advisory, number 6319983.

Set the controls CERT-UA recommends

CERT-UA advises restricting the Run dialog (Win+R) through Group Policy, limiting MSI installation to administrators, watching msiexec.exe, enabling the Microsoft vulnerable driver blocklist and allowlisting browser extensions. On the last point, Chrome and Edge both support an ExtensionInstallBlocklist of * with an ExtensionInstallAllowlist of approved IDs, which would have stopped LUNARAXE outright.

Given Ontinue's finding, do not treat the driver blocklist as enough. Add an explicit App Control for Business (WDAC) deny rule for PDFWKRNL.sys on machines that do not need it, and alert on any msiexec.exe process that fetches a package from a URL.

If you find it

Treat the machine as compromised at kernel level: reimage it rather than clean it. Removing the stealer while leaving the extension, the native messaging host and the Defender exclusions in place leaves the backdoor working. Then revoke sessions and reset passwords for every account used in that browser, since stolen cookies and tokens keep working after a password change until the session is revoked. Move any cryptocurrency from wallets on that machine to new keys.

The lesson for EDR monitoring

A blinded EDR agent still reports in as healthy, so "agent online" on the console says little about whether it can see anything. Alerts on driver installs and Defender exclusion changes are cheap to set up and catch this chain before the stealer runs.

Our safeguarding and hardening work covers extension allowlists, MSI and driver controls on Windows fleets, and our security operations team builds the detections for native messaging hosts, exclusion changes and driver loads. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.


Sources: CERT-UA advisory 6319983, Security Affairs, The Record, The Hacker News, Hackread, GBHackers, Cryptika, Ontinue, The Hacker News on the AMD driver, PolySwarm.

Back to the blog, or read this post on the full site.