LunexStealer (Psychedelic Stealer): UAC-0277 uses 100+ compromised websites to spread infostealer
08 Oct 2026
Security researchers have reported about the threat group UAC-0277 using more than 100 compromised websites to deliver malware through malicious JavaScript and a ClickFix style fake Cloudflare verification page.
Through our blog, we understand what the LunexStealer infostealer is about, the threat it poses, and what organizations can do to defend against it.
About LunexStealer (Psychedelic Stealer)
|
Threat name |
Threat actor |
Affected technology |
Threat type |
Primary techniques |
|
LunexStealer (Psychedelic Stealer) |
Microsoft Windows/Windows kernel |
Windows Systems / Web Browsers / MSI / PowerShell / Browser Extensions
|
Infostealer |
|
Victims are tricked into manually executing an attacker-provided command, which downloads a malicious MSI package that can deploy LunexStealer and additional components such as LUNARAXE and NAIVEMESS.
What is the threat posed by the infostealer?
If successfully executed, LunexStealer may help attackers:
- Steal browser credentials, cookies, history, and bookmarks.
- Target cryptocurrency wallets and browser extension data.
- Capture credentials entered into web forms.
- Install malicious browser extensions.
- Execute PowerShell-based post-exploitation activity.
- Modify Microsoft Defender exclusions.
- Attempt UAC bypass and security-tool evasion.
- Abuse vulnerable drivers such as PDFWKRNL.sys.
- Perform DLL sideloading through FnHotkeyUtility.exe → spkvol.dll.
- Establish persistence through Registry Run keys and Scheduled Tasks.
- Enable potential follow-on compromise using stolen credentials and session tokens.
SharkStriker’s recommendations
- Restrict MSI installation by standard users where feasible.
- Enable Microsoft’s ASR rule “Block abuse of exploited vulnerable signed drivers.”
- Monitor unauthorized Microsoft Defender exclusion changes.
- Review newly installed or suspicious browser extensions.
- Educate users that legitimate Cloudflare/CAPTCHA pages do not require manual command execution.
- Actively monitor the environment for LunexStealer indicators, suspicious MSI execution, browser-originated command execution, and credential theft activity.