Threat Intelligence

Fake Cloudflare Checks on 100+ Hacked Websites Are Tricking Visitors into Installing Data-Stealing Malware

The Hacker News · 7 Oct 2026
Key Takeaway Train staff never to paste or run commands from a website verification prompt, as genuine Cloudflare checks never ask for this, and review installed browser extensions for unfamiliar items.

Ukraine's national cyber response team, CERT-UA, has identified more than 100 compromised websites carrying malicious JavaScript that delivers an information-stealing program called LunexStealer (also known as Psychedelic Stealer). The activity was observed in September 2026 and attributed to a threat cluster tracked as UAC-0277. CERT-UA did not say who the victims were or whether any systems were actually compromised.

Visitors to affected sites see a forged Cloudflare page that claims to confirm they are human, then asks them to run a command. Doing so downloads and installs a malicious MSI package from a remote server, a method known as ClickFix. The fake page is shown only to Windows users who arrive from search engine results, and no more than twice in 12 hours. The attackers also use a technique called EtherHiding, which retrieves the lure's domain and the script's operating mode from a smart contract on the Polygon or Ethereum network.

Research from Arctic Wolf Labs and Ontinue shows LunexStealer also installs a browser extension called LUNARAXE, disguised as "Microsoft Office Word Editor". It can steal cookies, browsing history and credentials typed into web forms, and lets the operator control the browser remotely and run JavaScript on web pages. A helper component, NAIVEMESS, gives the extension access to the Windows file system.

LunexStealer ClickFix infostealer malicious browser extension CERT-UA

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.