UAC-0277 is an unidentified threat activity cluster tracked by Ukraine's Computer Emergency Response Team, CERT-UA, following a September 2026 campaign targeting Ukrainian Windows users. The campaign compromised more than 100 legitimate websites and injected JavaScript that presented counterfeit Cloudflare human-verification pages. These pages used ClickFix social engineering to persuade visitors to execute commands that downloaded and installed malicious Windows MSI packages. The operators' identity and country of origin have not been established, and the cluster has not been attributed to a known state-backed group. The campaign used EtherHiding to retrieve delivery destinations and operating settings from smart contracts on Polygon or Ethereum, allowing centralized configuration changes without modifying each compromised website. The injected scripts supported inactive operation, passive visitor tracking, and fake-verification delivery. Verification prompts selectively appeared to Windows users arriving through search engines. Three delivery variants installed LUNEXSTEALER directly, attempted User Account Control bypass and impaired security tools through a vulnerable AMD driver associated with CVE-2023-20598, or used DLL sideloading to decrypt and launch the payload. The vulnerable-driver variant also configured Microsoft Defender exclusions. LUNEXSTEALER, also known as Psychedelic Stealer, collects browser credentials, authentication tokens, cryptocurrency-wallet data, and system information, and supports remote command execution and additional payload deployment. It can establish scheduled-task persistence and install LUNARAXE, a malicious Chromium browser extension masquerading as Microsoft Office Word Editor. LUNARAXE steals cookies, browsing history, and credentials submitted through web forms, while enabling remote browser manipulation, screenshots, proxy changes, and webpage JavaScript execution. Its supporting NAIVEMESS component provides local directory enumeration, file reading and writing, file transfer, and program execution through browser native messaging. The extension can resume operation after browser restarts and removes webpage Content Security Policy protections. The number of successfully infected endpoints has not been established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
105 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
UAC-0277 operates a website-compromise campaign that selectively presents Windows visitors with fake human-verification prompts. These ClickFix prompts persuade users to execute commands that install LUNEXSTEALER through MSI packages. The malware steals credentials, authentication tokens, cryptocurrency wallet data, and system information, and supports additional downloads and remote commands. It can also deploy the LUNARAXE browser extension and NAIVEMESS component for browser surveillance, browser manipulation, and file-system access. The content does not establish the number of infected visitors, attacker origin, state sponsorship, or specific geographic or industry targeting.
UAC-0277 appears in the article's tags, but the body does not explicitly attribute the described LunexStealer campaign to this activity cluster.
CERT-UA attributes a September 2026 campaign involving more than 100 compromised websites to UAC-0277. Injected JavaScript displays fake Cloudflare verification pages that trick visitors into executing commands to install LunexStealer through malicious MSI packages. The malware supports browser-data theft, remote browser control, and filesystem access through additional components. Victim identities and successful endpoint compromises were not disclosed.
An unidentified activity cluster associated with the compromise of more than 100 Ukrainian websites to distribute Lunex Stealer. Injected JavaScript displayed fake Cloudflare verification prompts that persuaded visitors to execute commands installing the malware. The campaign sought browser credentials, authentication data and cryptocurrency-wallet information. The initial website compromise method, infection count and campaign status were not disclosed.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.