Back to Intelligence

UAC-0277 Fake Cloudflare Verification Pages Deliver LunexStealer: Detection and Response Guide

SA
Security Arsenal Team
October 7, 2026
12 min read

The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites injected with malicious JavaScript that serves fake Cloudflare verification checks — a lure designed to trick visitors into infecting themselves with LunexStealer (also tracked as Psychedelic Stealer), an information-stealing malware family. CERT-UA attributes the activity, observed in September 2026, to a threat cluster designated UAC-0277.

This campaign matters to every defender, not just those protecting Ukrainian assets. The fake Cloudflare "Verify you are human" page has become one of the most effective social engineering delivery mechanisms in the wild — commonly referred to as the ClickFix technique. Instead of exploiting a software vulnerability, it exploits the user's trust in a familiar security brand. The victim is instructed to manually execute a malicious command, typically via the Windows Run dialog, which hands execution to attacker-controlled PowerShell. From a detection engineering perspective, that shift is critical: your perimeter controls, sandboxing, and attachment filtering are all bypassed because the user is the execution vector. Once LunexStealer lands, it harvests browser credentials, session cookies, cryptocurrency wallets, and other high-value data — the raw material for account takeover, business email compromise, and follow-on ransomware access brokerage.

If your organization allows users to browse the web from endpoints that also hold corporate credentials, you are in scope for this threat. This post breaks down the attack chain, provides field-tested detection logic (Sigma, KQL, VQL), and gives you concrete hardening steps to reduce your exposure today.

Technical Analysis

Affected Platforms

  • Primary target: Windows endpoints used for web browsing (the ClickFix lure and LunexStealer payload are Windows-centric)
  • Delivery infrastructure: 100+ legitimate websites compromised and injected with malicious JavaScript; the sites themselves span multiple CMS platforms and are victims, not willing participants
  • Impersonated brand: Cloudflare (Turnstile-style "Verify you are human" interstitial pages)
  • Attribution: CERT-UA tracks the cluster as UAC-0277; no CVE is associated with this campaign because no software vulnerability is exploited — the delivery mechanism is pure social engineering

Attack Chain (Defender's View)

  1. Injection: Threat actors compromise legitimate websites and inject malicious JavaScript. Because the sites are otherwise benign and often well-ranked, they sail past URL reputation filters and carry inherent trust.
  2. Lure rendering: The injected script overlays or redirects to a convincing fake Cloudflare verification page. The page claims the user must complete a "verification" step to prove they are human.
  3. ClickFix execution handoff: Instead of a normal checkbox, the page instructs the user to press Win + R, paste a clipboard-copied command (the page silently copies it for them), and press Enter. This launches a PowerShell one-liner — typically a download cradle using iwr/irm piped to iex, or an mshta/rundll32 invocation pulling a remote payload.
  4. Payload staging: The cradle retrieves the LunexStealer binary (often via intermediate scripts or staged loaders) into a user-writable location such as %TEMP%, %APPDATA%, or %LOCALAPPDATA%, then executes it.
  5. Theft and exfiltration: LunexStealer targets browser credential stores (Chrome/Edge Login Data, cookies, autofill), cryptocurrency wallet extensions and desktop wallets, and other stored secrets. Data is staged, compressed, and exfiltrated to attacker-controlled C2.
  6. Cleanup/persistence (variable): Some stealer builds delete staging artifacts after exfiltration; others establish persistence via Run keys or scheduled tasks for repeat collection.

Exploitation Status

  • Confirmed active in the wild: CERT-UA has documented 100+ compromised sites actively serving the lure as of September–October 2026.
  • No CVE / not in CISA KEV: This is a social engineering and malware delivery campaign, not a vulnerability exploit. Patching will not save you here — detection engineering and user-behavior controls will.
  • Why it's effective: The victim self-executes the payload with their own user context, bypassing email gateways, attachment sandboxes, and most browser exploit defenses. EDR is your last line of defense.

Detection & Response

The highest-fidelity detection opportunities for ClickFix-style delivery cluster around one core anomaly: interactive shells (Explorer) or browser processes spawning script interpreters with download-cradle syntax. Legitimate software almost never does this. Secondary opportunities exist around unauthorized access to browser credential stores — the stealer's raison d'être.

Sigma Rules

The following rules target the behaviors described in the CERT-UA reporting. Tune parent-process lists to your environment, but resist the urge to broaden the command-line logic — the specificity is what keeps these quiet.

YAML
---
title: ClickFix-Style Download Cradle Spawned by Explorer or Browser
id: 3f9a1c72-8b4e-4d12-9f67-2a5c8e601d34
status: experimental
description: Detects script interpreters with download-cradle syntax spawned by Explorer or a browser process, consistent with fake Cloudflare verification (ClickFix) lures delivering LunexStealer via UAC-0277 compromised sites.
references:
  - https://thehackernews.com/2026/10/100-compromised-websites-use-fake.html
  - https://attack.mitre.org/techniques/T1204/
  - https://attack.mitre.org/techniques/T1059/001/
author: Security Arsenal
date: 2026/10/09
tags:
  - attack.execution
  - attack.t1059.001
  - attack.t1204
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\mshta.exe'
      - '\cmd.exe'
      - '\rundll32.exe'
      - '\curl.exe'
  selection_parent:
    ParentImage|endswith:
      - '\explorer.exe'
      - '\msedge.exe'
      - '\chrome.exe'
      - '\firefox.exe'
      - '\brave.exe'
      - '\opera.exe'
  selection_cli:
    CommandLine|contains:
      - 'iwr '
      - 'irm '
      - 'Invoke-WebRequest'
      - 'Invoke-RestMethod'
      - 'DownloadString'
      - 'DownloadFile'
      - 'Net.WebClient'
      - 'Start-BitsTransfer'
      - '| iex'
      - '|iex'
      - 'IEX('
      - 'FromBase64String'
      - ' -enc'
      - ' -e '
      - 'mshta http'
  condition: selection_img and selection_parent and selection_cli
falsepositives:
  - Rare; legitimate administrative download cradles are not typically launched from Explorer or browser parentage
level: high
---
title: Suspicious Process Access to Browser Credential Stores
id: 7c2e5b91-4d68-4f3a-b821-9e6a0d53c1f7
status: experimental
description: Detects non-browser processes reading browser Login Data, Cookies, or Web Data files, a hallmark of infostealers such as LunexStealer harvesting stored credentials and session tokens.
references:
  - https://thehackernews.com/2026/10/100-compromised-websites-use-fake.html
  - https://attack.mitre.org/techniques/T1555/003/
  - https://attack.mitre.org/techniques/T1539/
author: Security Arsenal
date: 2026/10/09
tags:
  - attack.credential_access
  - attack.t1555.003
  - attack.collection
  - attack.t1539
logsource:
  category: file_event
  product: windows
detection:
  selection_files:
    TargetFilename|contains:
      - '\Google\Chrome\User Data\'
      - '\Microsoft\Edge\User Data\'
      - '\BraveSoftware\Brave-Browser\User Data\'
      - '\Opera Software\Opera Stable\'
    TargetFilename|endswith:
      - '\Login Data'
      - '\Cookies'
      - '\Web Data'
      - '\Network\Cookies'
  filter_browser:
    Image|endswith:
      - '\chrome.exe'
      - '\msedge.exe'
      - '\brave.exe'
      - '\opera.exe'
      - '\msedgewebview2.exe'
  filter_sync:
    Image|contains:
      - '\Google\Chrome\Application\'
      - '\Microsoft\Edge\Application\'
  condition: selection_files and not filter_browser and not filter_sync
falsepositives:
  - Enterprise backup agents or DLP tools scanning user profiles; allowlist by known process hash/path after validation
level: high
---
title: Script Interpreter Executing from User Temp or AppData After Browser Activity
id: 1b8d4f06-9a37-4c55-ae02-6d7f3c84b590
status: experimental
description: Detects executables or script hosts running from user-writable Temp/AppData paths shortly after browser activity, consistent with staged LunexStealer payloads dropped by ClickFix download cradles.
references:
  - https://thehackernews.com/2026/10/100-compromised-websites-use-fake.html
  - https://attack.mitre.org/techniques/T1204/002/
author: Security Arsenal
date: 2026/10/09
tags:
  - attack.execution
  - attack.t1204.002
  - attack.t1059
logsource:
  category: process_creation
  product: windows
detection:
  selection_path:
    Image|contains:
      - '\AppData\Local\Temp\'
      - '\AppData\Roaming\'
      - '\AppData\Local\'
      - '\Users\Public\'
      - '\Downloads\'
  selection_type:
    Image|endswith:
      - '.exe'
      - '\powershell.exe'
      - '\wscript.exe'
      - '\cscript.exe'
      - '\mshta.exe'
  filter_known:
    Image|contains:
      - '\AppData\Local\Microsoft\Teams\'
      - '\AppData\Local\slack\'
      - '\AppData\Local\Discord\'
      - '\AppData\Roaming\Zoom\'
      - '\AppData\Local\Programs\'
  filter_installer:
    CommandLine|contains:
      - '/S'
      - '/quiet'
      - '--silent'
  condition: selection_path and selection_type and not filter_known and not filter_installer
falsepositives:
  - Electron-based apps and user-mode installers; baseline per-host over 7 days and allowlist recurring signed binaries
level: medium

Deployment note: Rule 2 requires Sysmon Event ID 11 (FileCreate) or, better, a targeted file-access auditing configuration on browser profile paths — enable it on a pilot ring first to measure volume. Rules 1 and 3 run fine on standard Sysmon process-creation telemetry.

KQL Hunting Query (Microsoft Sentinel / Defender)

This query hunts the ClickFix handoff: browsers or Explorer spawning script interpreters with download-cradle or encoded-command syntax. Run it across the last 14 days, then pivot on DeviceName and TimeGenerated for any hits.

KQL — Microsoft Sentinel / Defender
let Lookback = 14d;
let ScriptHosts = dynamic(["powershell.exe","pwsh.exe","mshta.exe","cmd.exe","rundll32.exe","wscript.exe","cscript.exe","curl.exe"]);
let CradlePatterns = dynamic(["iwr ","irm ","Invoke-WebRequest","Invoke-RestMethod","DownloadString","DownloadFile","Net.WebClient","Start-BitsTransfer","| iex","|iex","IEX(","FromBase64String","-enc "," -e ","mshta http"]);
let BrowserParents = dynamic(["explorer.exe","msedge.exe","chrome.exe","firefox.exe","brave.exe","opera.exe"]);
DeviceProcessEvents
| where TimeGenerated > ago(Lookback)
| where FileName in~ ScriptHosts
| where InitiatingProcessFileName in~ BrowserParents
| where ProcessCommandLine has_any (CradlePatterns)
| extend SuspicionScore = case(
    ProcessCommandLine has_any ("FromBase64String","-enc "," -e "), 3,
    ProcessCommandLine has_any ("| iex","|iex","IEX("), 2,
    1)
| project TimeGenerated, DeviceName, AccountName, InitiatingProcessFileName, FileName, ProcessCommandLine, ProcessId, InitiatingProcessId, SuspicionScore, ReportId
| order by SuspicionScore desc, TimeGenerated desc

Companion hunt — stealer staging directories: If you ingest Sysmon file events or Defender file events, pivot any host flagged above into recently created executables under %TEMP%, %APPDATA%, and %USERPROFILE%\Downloads within ±30 minutes of the process event. Also check DeviceNetworkEvents on the same host for outbound connections from unsigned processes immediately following the cradle execution — LunexStealer exfiltrates fast.

Velociraptor VQL Hunt

Use this artifact for a fleet-wide sweep looking for live or recent evidence of ClickFix-style execution and stealer staging. It combines process inspection with filesystem artifacts in user-writable paths.

VQL — Velociraptor
-- UAC-0277 / LunexStealer ClickFix hunt: suspicious cradles and staged payloads
LET procs = SELECT Pid, Ppid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE CommandLine =~ '(?i)(iwr |irm |invoke-webrequest|invoke-restmethod|downloadstring|downloadfile|net\.webclient|frombase64string|\| *iex|start-bitstransfer|mshta http)'
  AND Name =~ '(?i)(powershell|pwsh|mshta|cmd|rundll32|wscript|cscript|curl)'

LET staged = SELECT FullPath, Size, Mtime, Btime
FROM glob(globs=[
  'C:/Users/*/AppData/Local/Temp/*.exe',
  'C:/Users/*/AppData/Local/Temp/*.ps1',
  'C:/Users/*/AppData/Roaming/*/*.exe',
  'C:/Users/*/Downloads/*.exe'
])
WHERE Btime > now() - 86400*3
  AND NOT FullPath =~ '(?i)(google|microsoft|mozilla|discord|slack|zoom|spotify)'

SELECT 'suspicious_process' AS FindingType, Pid, Ppid, Name, CommandLine, Exe, Username, CreateTime AS EventTime, NULL AS FullPath, NULL AS Size
FROM procs
UNION ALL
SELECT 'recently_staged_file' AS FindingType, NULL AS Pid, NULL AS Ppid, NULL AS Name, NULL AS CommandLine, NULL AS Exe, NULL AS Username, Btime AS EventTime, FullPath, Size
FROM staged
ORDER BY EventTime DESC

For hosts with hits, follow up with SELECT * FROM netstat() scoped to the suspect Pid to identify exfiltration endpoints, and pull the browser History SQLite databases to identify the exact compromised site that served the fake Cloudflare page — that URL is reportable intelligence for your blocklists and for CERT-UA-style information sharing.

Remediation & Verification Script

Run this on suspected endpoints (or deploy via your RMM/EDR live-response console). It performs three functions: (1) confirms PowerShell logging posture, (2) sweeps for recently staged payloads in user-writable paths, and (3) dumps persistence autostart entries for review.

PowerShell
# UAC-0277 / LunexStealer triage and verification script - run elevated
# 1) Verify PowerShell Script Block Logging and Module Logging are enabled
$sbPath = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging'
if (-not (Test-Path $sbPath)) {
    New-Item -Path $sbPath -Force | Out-Null
    Set-ItemProperty -Path $sbPath -Name 'EnableScriptBlockLogging' -Value 1
    Write-Host '[+] Script Block Logging was DISABLED - now enabled for future detection.' -ForegroundColor Yellow
} else {
    Write-Host '[+] Script Block Logging already present.' -ForegroundColor Green
}

# 2) Sweep user-writable staging paths for executables/scripts created in the last 72 hours
$cutoff = (Get-Date).AddHours(-72)
$paths = @("$env:TEMP", "$env:LOCALAPPDATA", "$env:APPDATA", "$env:USERPROFILE\Downloads", 'C:\Users\Public')
$suspect = foreach ($p in $paths) {
    if (Test-Path $p) {
        Get-ChildItem -Path $p -Recurse -Include *.exe,*.ps1,*.bat,*.hta,*.js,*.vbs -ErrorAction SilentlyContinue |
            Where-Object { $_.CreationTime -gt $cutoff -and $_.FullName -notmatch 'Microsoft|Google|Mozilla|Discord|Slack|Zoom' }
    }
}
if ($suspect) {
    Write-Host '[!] Recently staged files found - collect hashes and submit to sandbox:' -ForegroundColor Red
    $suspect | Select-Object FullName, CreationTime, Length | Format-Table -AutoSize
    $suspect | ForEach-Object { Get-FileHash $_.FullName -Algorithm SHA256 } | Format-Table Hash, Path -AutoSize
} else {
    Write-Host '[+] No recently staged payloads found in user-writable paths.' -ForegroundColor Green
}

# 3) Dump persistence autostart locations for review (stealers often persist via Run keys)
Write-Host '[*] Current user and machine Run key entries:' -ForegroundColor Cyan
Get-ItemProperty 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Run' -ErrorAction SilentlyContinue
Get-ItemProperty 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Run' -ErrorAction SilentlyContinue
Get-ScheduledTask -ErrorAction SilentlyContinue | Where-Object { $_.Date -gt $cutoff } |
    Select-Object TaskName, TaskPath, Date | Format-Table -AutoSize

# 4) Optional hardening: block outbound web traffic from script hosts via Windows Firewall
# Uncomment to enforce - validate against your build tooling first
# New-NetFirewallRule -DisplayName 'Block PowerShell Outbound HTTP/S' -Direction Outbound `
#   -Program "$env:SystemRoot\System32\WindowsPowerShell\v1.0\powershell.exe" `
#   -Protocol TCP -RemotePort 80,443 -Action Block

Remediation

There is no patch for this campaign because there is no CVE — remediation is architectural and behavioral. Prioritize the following, in order of defensive return:

  1. Neutralize the ClickFix handoff. The single most effective control: prevent users from executing arbitrary commands via Win + R as a malware vector. Use Microsoft Defender Attack Surface Reduction (ASR) rule "Block execution of potentially obfuscated scripts" and, where operationally feasible, constrain PowerShell for standard users via AppLocker or Windows Defender Application Control (WDAC) policies that enforce Constrained Language Mode for non-administrative contexts.
  2. Enable and centralize PowerShell Script Block Logging (Event ID 4104) and Module Logging (4103). The fake-verification cradles are almost always one-liners containing iwr/irm/iex tokens — Script Block logs make them trivially searchable. Ship these to your SIEM.
  3. Browser and network controls. Deploy SmartScreen/Defender reputation-based blocking, and add DNS/web-filter detections for newly observed fake-verification redirectors. Block outbound TCP 80/443 from powershell.exe, pwsh.exe, mshta.exe, rundll32.exe, and wscript.exe at the endpoint firewall or proxy layer unless a documented exception exists. This breaks the download cradle even if the user executes it.
  4. Protect browser credential stores at the source. Enforce phishing-resistant MFA (FIDO2/passkeys) on all corporate identity providers — stolen cookies and passwords from LunexStealer are dramatically less valuable when sessions can't be replayed and credentials can't be reused. Consider moving users to browsers with app-bound encryption for cookie stores and restricting third-party cookie access.
  5. User awareness tuned to this exact lure. Generic phishing training does not cover ClickFix. Brief users specifically: no legitimate Cloudflare or CAPTCHA page will ever ask you to press Win+R and paste a command. Show them a screenshot of the fake verification flow. This campaign lives or dies on that one behavior.
  6. Webmaster guidance for the compromised-site side. If you operate public websites: audit for unauthorized JavaScript injection (review template files, CMS plugins, and third-party script tags), enforce Subresource Integrity on third-party scripts, deploy a restrictive Content Security Policy, and monitor for unexpected DOM overlays with a CSP report-uri endpoint.
  7. If compromise is confirmed: Isolate the host, collect memory and the staged binary, treat all credentials stored in or entered into browsers on that endpoint as compromised (force resets and session revocation), review IdP sign-in logs for token replay, and hunt laterally using the queries above. Report observed infrastructure to CERT-UA channels if your organization operates in or with Ukraine.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.