LunexStealer (Psychedelic Stealer): UAC-0277 uses 100+ compromised websites to spread infostealer

08 Oct 2026

Security researchers have reported about the threat group UAC-0277 using more than 100 compromised websites to deliver malware through malicious JavaScript and a ClickFix style fake Cloudflare verification page.

 

Through our blog, we understand what the LunexStealer infostealer is about, the threat it poses, and what organizations can do to defend against it.

About LunexStealer (Psychedelic Stealer)

Threat name 

Threat actor 

Affected technology 

Threat type 

Primary techniques 

LunexStealer (Psychedelic Stealer) 

Microsoft Windows/Windows kernel 

Windows Systems / Web Browsers / MSI / PowerShell / Browser Extensions 

 

Infostealer 

  • Compromised Websites 
  • Malicious JavaScript 
  • ClickFix 
  • Fake Cloudflare Verification 
  • MSI Execution 
  • UAC Bypass 
  • BYOVD 
  • DLL Sideloading 
  • Credential Theft Persistence 

 

Victims are tricked into manually executing an attacker-provided command, which downloads a malicious MSI package that can deploy LunexStealer and additional components such as LUNARAXE and NAIVEMESS.

What is the threat posed by the infostealer?

If successfully executed, LunexStealer may help attackers:

 

  • Steal browser credentials, cookies, history, and bookmarks.
  • Target cryptocurrency wallets and browser extension data.
  • Capture credentials entered into web forms.
  • Install malicious browser extensions.
  • Execute PowerShell-based post-exploitation activity.
  • Modify Microsoft Defender exclusions.
  • Attempt UAC bypass and security-tool evasion.
  • Abuse vulnerable drivers such as PDFWKRNL.sys.
  • Perform DLL sideloading through FnHotkeyUtility.exe → spkvol.dll.
  • Establish persistence through Registry Run keys and Scheduled Tasks.
  • Enable potential follow-on compromise using stolen credentials and session tokens.

SharkStriker’s recommendations

 

  • Restrict MSI installation by standard users where feasible.
  • Enable Microsoft’s ASR rule “Block abuse of exploited vulnerable signed drivers.”
  • Monitor unauthorized Microsoft Defender exclusion changes.
  • Review newly installed or suspicious browser extensions.
  • Educate users that legitimate Cloudflare/CAPTCHA pages do not require manual command execution.
  • Actively monitor the environment for LunexStealer indicators, suspicious MSI execution, browser-originated command execution, and credential theft activity.

Get in Touch With us

We have explored what risk tolerance and risk appetite are and how important they are together in helping businesses align cybersecurity with their business goals. It can help CISOs, and C-suite make informed investment decisions for cybersecurity.

LEARN MORE