LUNARAXE is a multicomponent malicious extension for Chromium-based browsers that combines browser-data theft with remote browser control. It is installed by LUNEXSTEALER according to command-and-control configuration and masquerades as Microsoft Office Word Editor. Observed deployments target Windows systems.
Its CORE component manages HTTP and WebSocket command-and-control communications and exfiltrates cookies, browsing history, bookmarks, installed-extension information, and intercepted credentials. Operators can manipulate browser tabs, capture tab screenshots, change proxy settings, enable or disable extensions, display notifications and deceptive overlays, and execute JavaScript on webpages. The STEALER component captures credentials entered into web forms and forwards them to CORE through internal extension messaging. The STRIP component removes Content Security Policy protections from HTTP responses and HTML metadata, facilitating script execution and data transmission. The background component resumes operation after browser restarts.
When the auxiliary NAIVEMESS component is installed, LUNARAXE gains access to the Windows filesystem through a PowerShell-based native messaging host. This combination supports drive and directory enumeration, file reading and writing, file transfer, and execution of local files. Browser-based access can persist after removal of the main LUNEXSTEALER executable.
LUNARAXE is associated with LUNEXSTEALER distribution activity tracked as UAC-0277, observed in September 2026 and targeting Windows users visiting compromised Ukrainian websites. That campaign used counterfeit Cloudflare verification pages and ClickFix social engineering to induce execution of commands that installed LUNEXSTEALER, which could subsequently deploy the extension.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Depending on instructions from its control server, LUNEXSTEALER can install LUNARAXE, a malicious extension for Chromium browsers.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malicious Chromium browser extension disguised as an office document editing tool. It collects cookies, browsing history, bookmarks, and credentials entered into website forms. Attackers can manipulate tabs, capture screenshots, change proxy settings, and execute JavaScript on webpages. It supports WebSocket-based remote interaction, resumes its background component after browser restarts, and uses NAIVEMESS to access the Windows file system. An additional extension component removes website security policies restricting scripts and data transfers.
Malicious browser extension installed by LunexStealer and disguised as Microsoft Office Word Editor. It steals cookies, browsing history, and credentials entered into web forms. It also enables remote browser control, including executing JavaScript, managing tabs, capturing tab snapshots, and changing proxy settings. When NAIVEMESS is present, it additionally gains access to the victim computer’s file system.
Browser extension providing information theft, remote browser control, and arbitrary JavaScript execution. Its LUNARAXE.CORE module manages C2 communications, executes commands, extracts browser data, manipulates tabs and extensions, and displays fake overlays. LUNARAXE.STEALER captures web-form credentials and their associated page URLs. LUNARAXE.STRIP removes Content Security Policy headers to facilitate arbitrary JavaScript execution. When NAIVEMESS is installed, the extension can also access, write, and execute files on the Windows host.
Malicious Chromium extension deployed in some Lunex infections. It reads cookies and browsing history, captures credentials entered into websites, manipulates tabs, executes JavaScript, takes screenshots and changes browser proxy settings. It can cooperate with NaiveMess to access files and execute programs outside the browser, potentially retaining attacker access after removal of the main Lunex executable.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.