A Fake Cloudflare Check Is Now the Front Door for a New Credential Stealing Browser Extension
Cybersecurity

A Fake Cloudflare Check Is Now the Front Door for a New Credential Stealing Browser Extension

CERT-UA found more than 100 compromised websites serving a forged Cloudflare verification page that tricks visitors into running a malicious installer. The payload includes a browser extension that masquerades as a Microsoft Office tool to harvest cookies and credentials.

PublishedOctober 7, 2026
Read time7 min read
Share

A verification page that asks you to run a command

CERT-UA, Ukraine's national computer emergency response team, disclosed a campaign in which more than 100 legitimate but compromised websites were injected with JavaScript designed to show visitors a forged Cloudflare verification screen. The page claims to be confirming that the visitor is a human rather than a bot, the same claim millions of legitimate Cloudflare checks make every day across the web. Instead of a simple checkbox, though, it instructs the visitor to copy a command and run it manually, the defining hallmark of the ClickFix technique that has quietly become one of the most reliable ways to get a user to infect their own machine without ever clicking a conventional malicious link or attachment.

Running the supplied command downloads and installs a malicious MSI package from a remote server, completing the infection chain the fake verification page exists to trigger. CERT-UA observed this activity throughout September 2026 and attributed it to a threat cluster it tracks internally as UAC-0277. The agency has not disclosed who the eventual victims were or confirmed exactly how many systems were compromised as a result, only that the infrastructure was actively serving the lure and that the underlying technique stayed consistent across every one of the compromised sites it examined in detail.

Infrastructure that lives on the blockchain

What sets this campaign apart operationally is how thoroughly it hides its own supporting infrastructure from conventional defensive tooling. The injected script uses a technique called EtherHiding to retrieve the domain currently hosting the fake verification page, along with which of three distinct operating modes to run, directly from a smart contract deployed on the Polygon or Ethereum network rather than from any conventional command server an analyst could trace. Mode zero stays inactive and does nothing. Mode one passively tracks visitors and quietly gathers data about the page that referred them. Mode two actually displays the fake verification screen, and does so only to Windows users who arrive from search engine results, never showing it more than twice to the same visitor within any twelve hour window.

Reading configuration from a public blockchain instead of a conventional domain or IP address means the takedown playbooks that work reliably against ordinary malicious infrastructure largely stop applying here. There is no domain registrar to notify about abuse and no hosting provider to pressure into pulling a server offline. The smart contract simply continues to sit on the network indefinitely, and its operators can update exactly what it serves to victims without ever touching the compromised websites themselves, which is precisely why this particular technique has been spreading rapidly across otherwise unrelated malware families throughout this year.

What actually lands on the machine

CERT-UA documented three distinct variants of the MSI package that the fake verification page ultimately delivers to a victim's machine. The first variant installs LunexStealer directly with no additional steps. A second variant first attempts to bypass Windows user account controls, configures specific exclusions inside Microsoft Defender, and abuses a legitimate but vulnerable AMD driver to blind installed security software before it finally retrieves and runs the stealer payload. A third variant sideloads the payload through a legitimate signed binary that gets tricked into loading a malicious DLL instead of its real one, which then decrypts and executes the stealer in memory. All three separate paths converge on the exact same final outcome regardless of which variant a given target happens to encounter.

Arctic Wolf Labs and Ontinue, working independently of each other, both confirmed that LunexStealer goes on to install a browser extension called LUNARAXE that masquerades convincingly as a Microsoft Office Word Editor extension. The disguise matters a great deal in practice, because employees are already conditioned by years of legitimate experience to trust an Office branded extension sitting in their browser toolbar without a second thought. Once installed, the extension quietly steals cookies, full browsing history, and anything typed into a web form, while also giving its operator the ability to control the browser remotely and run arbitrary JavaScript on any page the victim happens to visit afterward.

A second channel that bypasses the browser entirely

LunexStealer also deploys a separate component CERT-UA calls NAIVEMESS, which gives the browser extension a PowerShell based channel directly into the Windows file system through what is formally known as a native messaging host. CERT-UA described its functionality in plain, specific terms: the component retrieves the full list of drives, browses through directories at will, and reads, creates, overwrites, and executes files, transferring the resulting data in Base64 encoded chunks after first pre-archiving entire directories and file groups into ZIP packages ready for exfiltration. That design means the malware is never limited to whatever happens to be visible inside a single browser tab.

The browser extension itself is organized into clearly defined modules. One module handles all command and control communication and exfiltrates browser data including cookies, history, and installed extensions. A second module specifically captures credentials as they are typed into any web form, alongside the page URL where they were entered. A third module strips Content Security Policy headers from incoming web pages so that arbitrary attacker supplied JavaScript can run in places where it would ordinarily be blocked outright. CERT-UA is advising organizations to restrict regular users from invoking the Windows Run dialog, a basic and inexpensive control that would break the entire installer chain right at its very first step.

Why this matters well beyond Ukraine

UAC-0277's campaign targets website visitors broadly rather than any single specific industry or region, and ClickFix style lures using the exact same basic mechanics have already turned up across North America and Europe this year wearing entirely different branding. A fake Cloudflare check is specifically effective because it exploits a genuine, nearly universal user habit built up over years of browsing: clicking through a routine verification screen without reading it closely, because legitimate versions are everywhere online and almost never ask a visitor for anything beyond a simple checkbox or an occasional image puzzle.

Security awareness programs built primarily around spotting a suspicious link or a misspelled lookalike domain will not catch this particular technique at all. The compromised website hosting the lure is genuinely real, the Cloudflare branding displayed on the page looks entirely correct, and the only reliable tell is that a legitimate verification check never, under any circumstance, asks a human visitor to open a terminal window and paste in a command. That single fact belongs in every phishing and malware awareness briefing your security team runs with employees this quarter, stated explicitly rather than implied.

What to change on the defensive side

Technically, blocking EtherHiding style campaigns effectively means monitoring for browser traffic headed toward blockchain RPC endpoints from unexpected processes, not simply relying on the usual domain and IP reputation blocklists, since the malicious configuration itself never touches any conventional infrastructure that standard reputation feeds are built to track. Endpoint detection rules should also specifically flag the AMD driver abuse CERT-UA documented in detail, since a legitimate but known vulnerable driver being loaded outside its normal expected context is a reliable signal worth acting on regardless of which specific campaign happens to be using it at the time.

Operationally, restrict the Windows Run dialog for standard, non administrative users across your fleet, since every single variant CERT-UA documented depends entirely on a user manually executing a command to get the infection chain started. That is a genuinely cheap control to deploy relative to the real cost of a credential stealing browser extension sitting undetected inside your workforce's browsers for weeks, quietly harvesting whatever gets typed into a web form, including the exact login credentials for whatever SaaS platform your business actually depends on to run day to day operations.

Tagged#news#security#cybersecurity#breach#cisa#ransomware#zero-day#supply-chain#ai-security#malware#clickfix#cert-ua#lunexstealer#lunaraxe#etherhiding#blockchain-c2