Ukraine’s CERT-UA discovered more than 100 compromised websites used to distribute malware through a ClickFix attack technique.
Attackers injected malicious JavaScript into legitimate websites that could display a fake Cloudflare verification page. Instead of simply completing a CAPTCHA, victims were instructed to run a command, which downloaded and installed an MSI package from a remote server.
The campaign used a smart contract on the Polygon or Ethereum blockchain to store the domain used for the fake verification page and the script's operating mode. The compromised website reads the information each time the script runs, which allows attackers to change the delivery infrastructure without accessing the sites again.
The script implemented three modes - 0 for inactive, 1 for passive visitor tracking, and 2 for displaying the fake verification page. Mode 2 was limited to Windows users who reached the site from search engines and was triggered no more than twice within 12 hours.
CERT-UA analyzed three MSI variants. The first directly installed the LUNEXSTEALER ifostealer. The second used UAC bypass, added exclusions to Microsoft Defender, and exploited the vulnerable AMD driver (PDFWKRNL.sys) via CVE-2023-20598 using the Bring Your Own Vulnerable Driver (BYOVD) technique before downloading LUNEXSTEALER.
The third variant used DLL side-loading. A legitimate FnHotkeyUtility.exe loaded a malicious spkvol.dll, which decrypted and executed LUNEXSTEALER.
Depending on its configuration, LUNEXSTEALER could also install the LUNARAXE browser extension, disguised as “Microsoft Office Word Editor.”
The extension can steal cookies, browsing history and credentials entered into web forms. It can also remotely control browser tabs, execute JavaScript on web pages, create tab snapshots and modify proxy settings. With the additional NAIVEMESS component, it can access the victim’s file system.
CERT-UA tracks the activity under the cyber-threat cluster identifier UAC-0277.