NAIVEMESS is a PowerShell-based auxiliary malware component that gives the malicious LUNARAXE browser extension access to the Windows file system. LunexStealer installs it according to configuration received from its command-and-control server. It registers as a Native Messaging Host for Chromium-based browsers, including Google Chrome and Microsoft Edge, bridging browser-extension commands to local file operations.
NAIVEMESS supports drive enumeration, directory browsing, file reading, file creation and overwriting, and execution of local files. It transfers files in Base64-encoded chunks and packages directories or groups of files into ZIP archives for transfer. Commands arrive through LUNARAXE rather than an independent command-and-control connection. Together, the components enable remote file collection, modification, and program execution beyond the browser. Native messaging registration can survive browser and computer restarts, and removal of the main LunexStealer executable does not necessarily eliminate this access.
NAIVEMESS is associated with the LunexStealer ecosystem used in the UAC-0277 campaign targeting Windows users in Ukraine. That campaign distributed LunexStealer through compromised websites displaying fake Cloudflare verification challenges, using ClickFix social engineering to persuade visitors to execute commands that installed malicious MSI packages.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A supporting PowerShell component, NAIVEMESS, bridges the extension to the Windows file system.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PowerShell component supporting LUNARAXE by bridging the malicious browser extension to the Windows file system. It enables attackers to browse directories, read and write files, and launch files. Its native-messaging host is registered as com.lunex.explorer.
Auxiliary PowerShell component that registers as a browser-to-system messaging host, enabling the LUNARAXE extension to read, write, and launch files on the victim’s computer.
Companion component enabling drive enumeration, directory browsing, file reading, creation, overwriting, and execution. Files are transferred in Base64-encoded chunks, while directories and groups of files are first archived into ZIP files. NAIVEMESS has no independent C2 channel; commands arrive through LUNARAXE.
Component registered as a native messaging host for Chrome and Microsoft Edge that enables LunarAxe to interact with the host filesystem. It supports listing drives, browsing directories, reading or overwriting files, downloading data and running programs. Its registration can survive computer and browser restarts, contributing to persistent access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.