Interestana
Home/News/100+ Websites Compromised by LunexStealer via Fake Cloudflare Checks
The Hacker News••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

100+ Websites Compromised by LunexStealer via Fake Cloudflare Checks

100+ Websites Compromised by LunexStealer via Fake Cloudflare Checks

The Computer Emergency Response Team of Ukraine (CERT-UA) has identified over 100 compromised websites that are actively distributing an information-stealing malware known as LunexStealer, also referred to as Psychedelic Stealer. This malicious activity was observed by the agency in September 2026 and has been attributed to a threat cluster designated as UAC-0277. The compromised websites employ a deceptive tactic by injecting malicious JavaScript code that mimics legitimate Cloudflare security checks. When users visit these infected sites, they are presented with what appears to be a standard Cloudflare "checking your browser" page. However, this page is a facade designed to trick users into believing their connection is being secured. Instead, the malicious JavaScript executes in the background, downloading and installing the LunexStealer malware onto the victim's system. LunexStealer is an information-stealing malware, meaning its primary function is to pilfer sensitive data from infected computers. This data can include login credentials for various online accounts, financial information, browser cookies, and other personal details that can be exploited for fraudulent purposes. The threat cluster UAC-0277, responsible for this campaign, has not been further detailed by CERT-UA regarding its specific origins or motivations. The use of fake Cloudflare checks is a sophisticated social engineering technique that leverages the trust users place in well-known security services. By impersonating Cloudflare, the attackers aim to bypass user suspicion and increase the likelihood of successful malware delivery. This method exploits the common user experience of encountering browser checks on websites, making the malicious activity harder to detect. The CERT-UA report does not specify the exact number of users affected or the full scope of data compromised, but the involvement of over 100 websites indicates a significant distribution effort. The agency's findings highlight a growing trend of threat actors using advanced social engineering and impersonation tactics to distribute malware. The compromise of these websites suggests a potential vulnerability in the website hosting infrastructure or a successful phishing attack against website administrators, allowing the attackers to inject the malicious scripts. Further investigation into the specific vulnerabilities exploited and the full capabilities of the UAC-0277 threat cluster is likely ongoing. The CERT-UA's alert serves as a critical warning to users to be vigilant about unexpected security checks and to ensure their systems are protected with up-to-date antivirus software and security patches.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next