Ukraine's computer emergency response team, CERT-UA, says it found more than 100 compromised websites in September 2026 that had been seeded with malicious JavaScript. Visitors were shown a fake Cloudflare check that, in the name of proving they were human, told them to run a command. Doing so downloaded and installed an MSI package from a remote server, a social engineering trick known as ClickFix. CERT-UA tracks the activity as UAC-0277 and published its analysis with indicators.
The end goal is LUNEXSTEALER, a 64-bit Windows program that steals saved browser passwords and tokens, desktop and browser crypto-wallet data and system details, and can also download and run further programs, MSI packages, PowerShell scripts and commands.
The control switch lives on a blockchain
The injected script does not hard-code where the fake page comes from. CERT-UA says the domain and the script's operating mode are stored in a smart contract on the Polygon or Ethereum network and read on every run, so the attackers can swap domains or switch the campaign on and off centrally without going back into the hacked sites. Mode 0 does nothing, mode 1 quietly logs which site and referring page a visitor came from, and mode 2 shows the fake check.
Even then the lure is selective. The fake page only appeared to Windows users who arrived from search engines such as Google, DuckDuckGo, meta.ua or bigmir.net, and no more than twice in 12 hours.
Three installers, one stealer
CERT-UA examined three MSI variants. The first installs LUNEXSTEALER directly. The second carries a loader that tries to bypass Windows User Account Control, adds Microsoft Defender exclusions, then deploys the vulnerable AMD driver PDFWKRNL.sys and exploits CVE-2023-20598 to weaken security tools (a bring-your-own-vulnerable-driver technique) before fetching the stealer. The third sideloads it: a legitimate FnHotkeyUtility.exe loads a malicious spkvol.dll that decrypts and runs LUNEXSTEALER.
A browser extension posing as Word
Depending on its configuration, LUNEXSTEALER can install LUNARAXE, a malicious Chromium extension that shows up as "Microsoft Office Word Editor". It steals cookies, browsing history and credentials typed into web forms, and lets the operators run JavaScript on pages, control and screenshot tabs and change proxy settings. One component strips Content Security Policy headers so the rest can run on locked-down sites. With a PowerShell helper called NAIVEMESS, registered as the native messaging host "com.lunex.explorer", the extension can also read, write and launch files on the computer.
Block Win+R and msiexec from URLs
CERT-UA stresses that no legitimate "I'm not a robot" check ever asks you to press Win+R, open a command prompt or PowerShell, or paste a command. Close the page, even on a site you know. For administrators it recommends:
- disabling the Run dialog (Win+R) for ordinary users through Group Policy;
- restricting MSI installs by non-admin users and monitoring msiexec.exe launched with a URL on the command line;
- enabling the Microsoft Vulnerable Driver Blocklist;
- allowlisting permitted browser extensions.
Selected indicators (defanged): uasputnik[.]com, sputnk[.]com, uasputn[.]com, ahahahahadebili[.]help, ukrainerada[.]top, 193[.]178[.]159[.]128, 107[.]175[.]82[.]242, and the scheduled task psychedelicloveUtils. The full list is in CERT-UA's report.
The campaign follows other fake CAPTCHA chains aimed at Ukrainians, including one that reached a government network. More of Ukraine's threat picture is on our Ukraine profile. What stands out is the blockchain switch, which lets the operators repoint the whole campaign without touching a single hacked site again. CERT-UA asks owners of compromised sites to contact it for help working out how they were breached.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.