Hackers Compromise 100+ Websites With Fake Cloudflare Checks to Spread LUNEXSTEALER
Attackers compromised over 100 sites with fake Cloudflare checks to install Windows infostealer LUNEXSTEALER.
CERT-UA, tracking the activity as UAC-0277, said attackers compromised more than 100 websites in September 2026 and used fake Cloudflare verification pages to spread the Windows malware LUNEXSTEALER. A ClickFix prompt told selected Windows visitors arriving from search engines to run a command that installed a remote MSI. Campaign mode and domains were retrieved from smart contracts on Polygon or Ethereum. The stealer collects browser passwords, tokens, wallet data, and system information, can install the LUNARAXE Chromium extension and NAIVEMESS PowerShell component, and one loader attempts UAC bypass, Defender exclusions, and abuse of AMD driver flaw CVE-2023-20598.
- Over 100 compromised sites showed fake Cloudflare checks to selected visitors.
- ClickFix makes users run a command that installs a Windows MSI.
- Campaign settings were pulled from Polygon or Ethereum smart contracts.
- LUNEXSTEALER steals browser secrets and can load the LUNARAXE extension.
- A loader abuses CVE-2023-20598 and adds Microsoft Defender exclusions.
Vulnerabilities mentionedAll →
- CVE-2023-205987.8<1%An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control over…published · amd radeon software
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-20598 | An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control over… An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control over arbitrary hardware ports or physical addresses resulting in a potential arbitrary code execution. |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | ahahahahadebili.help | ture. IPv4 159[.]69.234.218 Campaign infrastructure. Domain ahahahahadebili[.]help Domain appearing in script and installer URLs. Domain fsp |
| domain | astratechuthree.top | cript URL. Domain radaukraine[.]top Campaign domain. Domain astratechuthree[.]top Campaign domain. Domain spectre.pp[.]ua Domain appearing |
| domain | flareru.live | n domain. Domain vibestglobal[.]com Campaign domain. Domain flareru[.]live Campaign domain. Domain plerdgate[.]com Campaign domain. |
| domain | fsputnik.com | ]help Domain appearing in script and installer URLs. Domain fsputnik[.]com Campaign domain. Domain sputnk[.]com Domain appearing in |
| domain | ilovecutecatetetes.click | re.pp[.]ua/spectre.msi MSI download location. URL https[:]//ilovecutecatetetes[.]click Additional URL listed by CERT-UA. URL https[:]//ilovecute |
| domain | ilovecutecatics.com | tes[.]click Additional URL listed by CERT-UA. URL https[:]//ilovecutecatics[.]com Additional URL listed by CERT-UA. URL fragment htt [ ]//i |
Full article1,438 words · extracted from cybersecuritynews.com · click to collapse
Hackers compromised more than 100 websites and used fake Cloudflare verification pages to spread LUNEXSTEALER, a Windows malware capable of stealing information and accepting remote commands.
The campaign turned visits to legitimate websites into opportunities to infect visitors’ computers. The attackers added malicious JavaScript to website pages, making a familiar security check the starting point for infection.
Similar fake Cloudflare verification attacks have used this approach to persuade visitors to run commands rather than download an obviously suspicious attachment. CERT-UA researchers identified the activity in September 2026 and tracked it as UAC-0277.
CERT-UA said in a report shared with Cyber Security News (CSN), published September 30, that its analysts examined three installer variants used to deliver the malware.
The malware can collect saved browser passwords, authentication tokens, cryptocurrency wallet data, and system information.
Its remote execution features extend the risk beyond information theft, allowing attackers to download additional software and issue commands. The advisory does not establish how many visitors were infected.
Hackers Compromise 100+ Websites With Fake Cloudflare Checks
The fake page asked visitors to execute a command to prove they were human. Following that instruction downloaded and installed a Windows MSI package from a remote server. This technique, known as ClickFix, relies on users performing the dangerous action themselves.
The injected script retrieved its operating mode and verification domain from a smart contract on the Polygon or Ethereum network. That arrangement let attackers change the campaign’s destination centrally without returning to each compromised website to edit its code.
Three modes controlled its behavior: inactive, passive visitor tracking, and fake verification display. Passive tracking sent information about the compromised website and the referring page to attacker infrastructure, while the active mode presented the deceptive challenge.
The challenge appeared only to Windows users arriving through search engines, including Google and DuckDuckGo. It was shown no more than twice within 12 hours, making exposure selective rather than displaying the same malicious prompt to every visitor.
.webp)
One installer deployed LUNEXSTEALER directly. Another used a loader that attempted to bypass Windows User Account Control, added Microsoft Defender exclusions, and exploited CVE-2023-20598 in a vulnerable AMD driver to interfere with security tools.
This mirrors vulnerable Windows driver abuse seen in other attacks, where legitimate but flawed drivers help undermine defenses. A third installer used a legitimate executable to load a malicious library, which decrypted and launched the stealer.
Browser Takeover
Depending on instructions from its control server, LUNEXSTEALER can install LUNARAXE, a malicious extension for Chromium browsers.
The extension disguises itself as an office document editing tool while collecting cookies, browsing history, bookmarks, and credentials entered into website forms.
Its capabilities resemble malicious browser extension backdoors that combine surveillance with remote control. Attackers can manipulate tabs, capture screenshots, change proxy settings, and execute JavaScript on webpages, giving them visibility into browsing activity and control over what victims see.
A supporting PowerShell component, NAIVEMESS, bridges the extension to the Windows file system. Through it, attackers can browse directories, read and write files, and launch them.
Another extension component removes website security policies that restrict scripts and data transfers. The malware communicates with its control server over HTTP, while the extension also supports WebSocket connections for remote interaction.
Its background browser component resumes after a browser restart, and the stealer can create a scheduled task to maintain access on infected systems.
CERT-UA stresses that genuine human verification never requires opening the Windows Run dialog, a command prompt, or PowerShell to paste and execute commands. Users encountering such instructions should close the page, even when the website is familiar.
Administrators should restrict ordinary users’ access to the Run dialog through group policies and limit MSI installation without administrator rights.
CERT-UA also recommends monitoring installer launches containing URLs, enabling Microsoft’s vulnerable driver blocklist, and permitting only approved browser extensions.
Suspected fake verification pages should be reported to CERT-UA. Owners or administrators of compromised websites can contact the team for practical assistance and guidance on determining how attackers gained access.
Indicators of compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.