100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer
thehackernews.com Oct 7, 2026

100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer

AI-summarised brief · reviewed before publication

CERT‑UA uncovered over 100 compromised sites that inject malicious JavaScript to deliver LunexStealer, a data‑stealing malware. The attacks, linked to threat cluster UAC‑0277, use forged Cloudflare verification pages to prompt users to run a command that downloads an MSI package via ClickFix. The malware installs a browser extension, LUNARAXE, and a native messaging host, NAIVEMESS, enabling file system access and remote command execution. CERT‑UA recommends restricting MSI execution, blocking vulnerable drivers, and limiting browser extensions.

💡 Why It Matters

  • · The campaign demonstrates how attackers blend social engineering with blockchain‑based command retrieval, expanding the attack surface for credential theft and remote control.