Known malicious kitcriticalstealer

UAC-0277 (LunexStealer): fake-Cloudflare ClickFix injection on compromised sites

family: uac0277-lunexstealer-2026-10

UAC-0277: script injected into compromised, mostly Ukrainian, websites. The current version reads a traffic-distribution (TDS) domain and an on/off mode from a Polygon smart contract (EtherHiding: eth_call to getConfig() through public RPC nodes) and, when switched on, shows Windows visitors who arrive from a search engine a fake Cloudflare check that asks for Win+R, Ctrl+V and Enter. The pasted command runs msiexec against a remote MSI that installs the LunexStealer infostealer, which can add a malicious browser extension posing as 'Microsoft Office Word Editor'. An earlier version of the injection (seen from August 2026) is a short stub that builds a deferred script from character codes and base64-decodes its source to <tds-host>/tds/tracker.js or /tds/new.js.

Anchors

YARA ruleUAC0277_Polygon_TDS_Loader
SMQL queryrun
yara_rule:UAC0277_Tracker_Stub OR contacted_host:fsputnik.com OR contacted_host:flareua.live OR contacted_host:flareru.live OR contacted_host:uasputnik.com OR contacted_host:partaonline.click OR contacted_host:vibestglobal.com OR contacted_host:plerdgate.com OR contacted_host:vatra.pp.ua OR contacted_host:fainomedia.pp.ua OR contacted_host:trembita.pp.ua OR contacted_host:lunelle.click OR contacted_host:violea.click OR contacted_host:lumelle.click OR contacted_host:solivellse.online OR contacted_host:velamira.online OR contacted_host:amavelle.online OR contacted_host:auriselle.online OR contacted_host:elavelle.online OR contacted_host:olivelle.online

Provenance

Added: 2026-10-07 11:55
One hunt for the whole campaign. YARA anchor: the current loader, <script data-contract="0x..."> with its obfuscated string table (/tds/tds.php, /banner.html, the fullscreen iframe id, the getConfig selector); contract seen 0x8e02b8245a416f7ea713f559c674d99fa2f979f9 (Polygon). Search anchor: pages matching the first-generation stub rule (UAC0277_Tracker_Stub), or that contacted a host which served the stub, the fake check or the MSI, or one of the last TDS domains before the operator switched the loader off on 2026-10-05: fsputnik[.]com, flareua[.]live, flareru[.]live, uasputnik[.]com, partaonline[.]click, vibestglobal[.]com, plerdgate[.]com, vatra[.]pp[.]ua, fainomedia[.]pp[.]ua, trembita[.]pp[.]ua, lunelle[.]click, violea[.]click, lumelle[.]click, solivellse[.]online, velamira[.]online, amavelle[.]online, auriselle[.]online, elavelle[.]online, olivelle[.]online. The older TDS domains rotated every few hours to days and are not listed. An infected site keeps the loader while the TDS is switched off, so a sighting can show a normal-looking page.

Sightings (5)

HostScanScriptMatchWhen
fenix.net.ua6139767a…—query2026-10-07 12:38
kilimi.com.uae9c23a38…—query2026-10-07 12:38
kolesa.dp.uad491df9b…https://kolesa.dp.ua/wide-tires#htmlyara2026-10-07 11:56
fenix.net.ua6139767a…https://fenix.net.ua/uk/golovna/#htmlyara2026-10-07 11:56
gigistore.com.ua4fc596f8…https://gigistore.com.ua/#htmlyara2026-10-07 11:56