What happened
Security researchers have tracked more than 100 compromised websites serving a convincing but entirely fake Cloudflare "verify you are human" prompt. Instead of confirming the visitor is human, the page tricks them into copying and running a command on their own machine — a technique known as ClickFix. That command downloads and installs a malicious MSI package carrying LunexStealer (also tracked as Psychedelic Stealer), an information-stealing malware family.
The activity, observed through September 2026, has been linked to a threat cluster tracked as UAC-0277. To make takedown harder, the attackers hide the address of their malware-hosting server inside a smart contract on a public blockchain (Polygon or Ethereum) — a technique called EtherHiding — rather than a domain that can simply be seized or blocklisted.
The compromised pages are selective about who they target: Windows visitors arriving from a search-engine result are the ones shown the fake verification screen, and only up to twice within a 12-hour window, which helps the campaign stay under the radar of automated scanners.
Researchers have identified at least three variants of the malicious installer. One simply drops LunexStealer. A second attempts to bypass Windows User Account Control, disables Microsoft Defender protections, and abuses a legitimate-but-vulnerable AMD driver to blind security tools before fetching the stealer remotely. A third loads the payload through DLL sideloading — smuggling a malicious library alongside a legitimate, signed executable so it runs with that program's trust.
Why it matters
LunexStealer doesn't stop at credential theft on the infected host. It installs a rogue browser extension disguised as a Microsoft Office add-in, which can read cookies, browsing history, and anything typed into a web form, and gives the attacker the ability to remotely control the browser and run arbitrary JavaScript on pages a victim visits. A companion component extends that access to the victim's file system, letting the attacker browse drives, read and overwrite files, and pull data out in archived, encoded chunks — all routed through the browser extension's own command channel rather than a separate, more easily detected C2 connection. The extension can also strip Content-Security-Policy headers from pages, removing a browser-level defense that would otherwise block injected scripts.
Because the lure relies on a fake, very ordinary-looking "prove you're not a robot" step, and the payload delivery chain blends legitimate Windows tooling (MSI installers, signed binaries, DLL sideloading) with living-off-the-land techniques, this campaign is built to slip past users and basic security tooling alike.
What to do
- Treat any verification page that asks you to copy, paste, and run a command as malicious — legitimate CAPTCHA and bot-check flows never require this.
- Restrict installation of MSI packages to administrators, and monitor or restrict unauthorized use of
msiexec.exe. - Apply Microsoft's vulnerable driver blocklist and enable the Attack Surface Reduction rule that blocks abuse of exploited, vulnerable signed drivers.
- Lock down browser extension installation to an allowlist, and periodically audit installed extensions for anything unrecognized or requesting excessive permissions.
- Restrict regular users' access to the Windows Run dialog via group policy to reduce the blast radius of ClickFix-style lures.
