Fake Cloudflare Checks on 100+ Hacked Websites Are Tricking Visitors into Installing Data-Stealing Malware
Ukraine's national cyber response team, CERT-UA, has identified more than 100 compromised websites carrying malicious JavaScript that delivers an information-stealing program called LunexStealer (also known as Psychedelic Stealer). The activity was observed in September 2026 and attributed to a threat cluster tracked as UAC-0277. CERT-UA did not say who the victims were or whether any systems were actually compromised.
Visitors to affected sites see a forged Cloudflare page that claims to confirm they are human, then asks them to run a command. Doing so downloads and installs a malicious MSI package from a remote server, a method known as ClickFix. The fake page is shown only to Windows users who arrive from search engine results, and no more than twice in 12 hours. The attackers also use a technique called EtherHiding, which retrieves the lure's domain and the script's operating mode from a smart contract on the Polygon or Ethereum network.
Research from Arctic Wolf Labs and Ontinue shows LunexStealer also installs a browser extension called LUNARAXE, disguised as "Microsoft Office Word Editor". It can steal cookies, browsing history and credentials typed into web forms, and lets the operator control the browser remotely and run JavaScript on web pages. A helper component, NAIVEMESS, gives the extension access to the Windows file system.