importantSYS.SOURCE: The Hacker News• 2026-10-07T12:27:54+05:30
100+ Compromised Websites Exploit Fake Cloudflare Checks to Distribute LunexStealer
Over 100 compromised websites use fake Cloudflare verification pages to deliver the LunexStealer malware, employing techniques like ClickFix and EtherHiding. The malware steals sensitive data, installs a malicious browser extension, and leverages vulnerable drivers to evade detection.
The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer).
The activity, which was observed by the agency in September 2026, has been attributed to a threat cluster dubbed UAC-0277. It did not disclose who the
*** END OF TRANSMISSION ***