100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer
AI-summarised brief · reviewed before publication
CERT‑UA uncovered over 100 compromised sites that inject malicious JavaScript to deliver LunexStealer, a data‑stealing malware. The attacks, linked to threat cluster UAC‑0277, use forged Cloudflare verification pages to prompt users to run a command that downloads an MSI package via ClickFix. The malware installs a browser extension, LUNARAXE, and a native messaging host, NAIVEMESS, enabling file system access and remote command execution. CERT‑UA recommends restricting MSI execution, blocking vulnerable drivers, and limiting browser extensions.
💡 Why It Matters
- · The campaign demonstrates how attackers blend social engineering with blockchain‑based command retrieval, expanding the attack surface for credential theft and remote control.