UAC-0277 (LunexStealer): fake-Cloudflare ClickFix injection on compromised sites
UAC-0277: script injected into compromised, mostly Ukrainian, websites. The current version reads a traffic-distribution (TDS) domain and an on/off mode from a Polygon smart contract (EtherHiding: eth_call to getConfig() through public RPC nodes) and, when switched on, shows Windows visitors who arrive from a search engine a fake Cloudflare check that asks for Win+R, Ctrl+V and Enter. The pasted command runs msiexec against a remote MSI that installs the LunexStealer infostealer, which can add a malicious browser extension posing as 'Microsoft Office Word Editor'. An earlier version of the injection (seen from August 2026) is a short stub that builds a deferred script from character codes and base64-decodes its source to <tds-host>/tds/tracker.js or /tds/new.js.
Anchors
yara_rule:UAC0277_Tracker_Stub OR contacted_host:fsputnik.com OR contacted_host:flareua.live OR contacted_host:flareru.live OR contacted_host:uasputnik.com OR contacted_host:partaonline.click OR contacted_host:vibestglobal.com OR contacted_host:plerdgate.com OR contacted_host:vatra.pp.ua OR contacted_host:fainomedia.pp.ua OR contacted_host:trembita.pp.ua OR contacted_host:lunelle.click OR contacted_host:violea.click OR contacted_host:lumelle.click OR contacted_host:solivellse.online OR contacted_host:velamira.online OR contacted_host:amavelle.online OR contacted_host:auriselle.online OR contacted_host:elavelle.online OR contacted_host:olivelle.onlineProvenance
Sightings (5)
| Host | Scan | Script | Match | When |
|---|---|---|---|---|
| fenix.net.ua | 6139767a… | — | query | 2026-10-07 12:38 |
| kilimi.com.ua | e9c23a38… | — | query | 2026-10-07 12:38 |
| kolesa.dp.ua | d491df9b… | https://kolesa.dp.ua/wide-tires#html | yara | 2026-10-07 11:56 |
| fenix.net.ua | 6139767a… | https://fenix.net.ua/uk/golovna/#html | yara | 2026-10-07 11:56 |
| gigistore.com.ua | 4fc596f8… | https://gigistore.com.ua/#html | yara | 2026-10-07 11:56 |