Hackers Compromise 100+ Websites With Fake Cloudflare Checks to Spread LUNEXSTEALER
Attackers compromised over 100 sites with fake Cloudflare checks to install Windows infostealer LUNEXSTEALER.
CERT-UA, tracking the activity as UAC-0277, said attackers compromised more than 100 websites in September 2026 and used fake Cloudflare verification pages to spread the Windows malware LUNEXSTEALER. A ClickFix prompt told selected Windows visitors arriving from search engines to run a command that installed a remote MSI. Campaign mode and domains were retrieved from smart contracts on Polygon or Ethereum. The stealer collects browser passwords, tokens, wallet data, and system information, can install the LUNARAXE Chromium extension and NAIVEMESS PowerShell component, and one loader attempts UAC bypass, Defender exclusions, and abuse of AMD driver flaw CVE-2023-20598.