#8
The Hacker News
general
October 07, 2026 at 06:57 UTC
100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer
By [email protected] (The Hacker News)
AI Summary
CERT-UA identified over 100 compromised Ukrainian websites injected with malicious JavaScript serving LunexStealer (also known as Psychedelic Stealer), in a ClickFix-style campaign that uses fake Cloudflare verification pages. The activity, observed in September 2026, has been attributed to threat cluster UAC-0277. The technique of abusing trusted infrastructure prompts to deliver infostealers continues to evolve, making it difficult for end users to distinguish legitimate browser security checks from malicious ones.
Relevance score: 74.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →