Malicious Chrome Extension LUNARAXE Turns Compromised Sites Into Remote‑Control Gateways
Security researchers have traced a coordinated distribution effort that installs the Windows infostealer known as LUNEXSTEALER on unsuspecting computers. The campaign hinges on a counterfeit browser add‑on called LUNARAXE, which grants attackers full remote control of the victim's Chromium‑based browsers once the extension is loaded.
More than a hundred compromised websites serve as the delivery network for the payload. By injecting the malicious installer into legitimate‑looking pages, the operators can reach a broad audience without drawing immediate attention, leveraging the trust users place in familiar domains.
LUNEXSTEALER itself is a classic infostealer: once on a Windows machine it harvests saved passwords, cookies, and other sensitive data. Its most insidious component is the bundled Chrome extension, which pretends to be a “Microsoft Office Word Editor” within the browser’s extension manager, a disguise designed to blend in with productivity tools that many users already have installed.
When a victim accepts the extension, LUNARAXE establishes a persistent channel to the attacker’s command server. Through this channel, the threat actors can inject arbitrary JavaScript, capture keystrokes, manipulate web sessions, and exfiltrate data in real time. The remote‑control capability effectively turns the compromised browser into a foothold for further exploitation of online accounts.
Experts advise users to audit their extension lists regularly, removing any that are unknown or poorly described. Keeping browsers and operating systems patched, employing reputable anti‑malware solutions, and restricting the installation of extensions to verified sources are also recommended mitigations. Organizations should consider deploying web‑filtering rules to block downloads from the identified compromised domains.
The LUNEXSTEALER operation underscores a growing trend in which cybercriminals weaponize browser extensions as a delivery mechanism for broader malware families. As browsers become more central to daily workflows, the security community is calling for tighter vetting processes in extension stores and improved behavioral detection to spot extensions that act beyond their declared purpose. The campaign, first reported by GBHackers, is still active, and investigators continue to monitor its evolution.
Comments (0)
Be the first to comment.
Join the discussion