Close Menu
NCIJ Network NCIJ Network
    What's Hot

    I see what’s happening here in Paris: reasonable student demands met with awful violence | Helen Massy-Beresford

    October 7, 2026

    Is Kennedy Center selling its Steinway pianos?

    October 7, 2026

    Russia ‘pursuing strategy of terror’, EU’s von der Leyen says after deadly strikes on Ukraine – Europe live | Europe

    October 7, 2026
    Facebook X (Twitter) Instagram
    Trending
    • I see what’s happening here in Paris: reasonable student demands met with awful violence | Helen Massy-Beresford
    • Is Kennedy Center selling its Steinway pianos?
    • Russia ‘pursuing strategy of terror’, EU’s von der Leyen says after deadly strikes on Ukraine – Europe live | Europe
    • EU-Parlament verschärft vor Šefčovič-Reise Haltung zur China-Politik – POLITICO
    • Apparent exodus of super-rich suggests UK is no longer billionaires’ playground | The super-rich
    • Welsh Green Party deputy Phil Davies resigns over Zionism motion
    • AI computing startup Lambda to raise $4B ahead of planned IPO
    • Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, October 7
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 7, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananOct 07, 2026Malware / Web Security

    The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer).

    The activity, which was observed by the agency in September 2026, has been attributed to a threat cluster dubbed UAC-0277. It did not disclose who the victims of the campaign were or if any systems were successfully compromised as a result of these attacks.

    “When visiting such a site, users were shown a forged Cloudflare verification page that, under the pretext of confirming the visitor is human, prompted them to execute a command,” CERT-UA said in an advisory. “Executing the command caused a malicious MSI package to be downloaded and installed from a remote server (the ClickFix technique).”

    The attacks also make use of the EtherHiding technique to retrieve the domain name of the resource from which the fake verification page is loaded, as well as the script’s operating mode, from a smart contract on the Polygon or Ethereum network.

    According to CERT-UA, there are three operating modes: 0 – inactive; 1 – passive tracking of visitors that includes gathering data about the website and the page from which the visitor arrived; and 2 – displaying the fake verification page.

    Cybersecurity

    In Mode 2, the bogus verification page is shown only to Windows users who arrive at the site from search engine results and not more than twice in 12 hours. These ClickFix lures lead to the distribution of MSI packages that deliver LunexStealer.

    At least three different variants of the MSI packages have been discovered –

    • Variant 1, which installs LunexStealer on the system.
    • Variant 2, which attempts to bypass Windows account control (UAC), configures Microsoft Defender exclusions, leverages the legitimate-but-vulnerable AMD driver (“PDFWKRNL.sys”) to blind security software, and then retrieves and runs LunexStealer from a remote server.
    • Variant 3, which launches LunexStealer via DLL sideloading by using the legitimate binary (“FnHotkeyUtility.exe”) to load a rogue DLL (“spkvol.dll”), which decrypts and executes the stealer.

    As documented by both Arctic Wolf Labs and Ontinue, LunexStealer is also designed to install a malicious browser extension called LUNARAXE. The extension masquerades as “Microsoft Office Word Editor” to steal cookies, browsing history, and credentials entered into web forms. It also allows the operator to remotely control the browser and execute arbitrary JavaScript on web pages.

    The stealer also deploys an auxiliary component named NAIVEMESS that’s installed based on a configuration received from the command-and-control (C2) server. Its primary responsibility is to provide LUNARAXE with access to the Windows file system through a PowerShell-based Native Messaging Host.

    “NAIVEMESS functionality includes retrieving the list of drives, browsing directories, reading, creating and overwriting files, as well as executing them,” CERT-UA said. “Files are transferred in chunks encoded in Base64, and directories and file groups are pre‑archived into ZIP.”

    Cybersecurity

    The component does have its own communication channel with the C2 server. Rather, commands are received via the extension, which houses three other modules –

    • LUNARAXE.CORE, which handles C2 communication, receives commands, executes them, and exfiltrates browser data (i.e., cookies, browsing history, bookmarks, details about installed extensions, and intercepted credentials). It can also manage tabs, enable/disable extensions, serve notifications, run JavaScript on web pages, and display bogus overlays. It can also copy files from the computer, write files to it, and execute them if NAIVEMESS is installed.
    • LUNARAXE.STEALER, which captures credentials entered into web forms and sends them to LUNARAXE.CORE, along with the page URL.
    • LUNARAXE.STRIP, which disables Content Security Policy (CSP) protections on web pages by stripping CSP headers from HTTP responses with an aim to run arbitrary JavaScript code.

    CERT-UA is advising organizations to prohibit regular users from using the Windows Run dialog via group policies, restrict the installation of MSI packages by users without administrator rights, monitor for the execution of “msiexec.exe,” enable blocking of vulnerable drivers via Microsoft’s vulnerable driver blocklist, and limit the installation of browser extensions to allowlisted ones.

    Microsoft also recommends turning on the Attack Surface Reduction (ASR) rule “Block abuse of exploited vulnerable signed drivers” to prevent an application from writing a vulnerable signed driver to disk.

    checks Cloudflare Compromised deliver Fake LunexStealer websites
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws

    Hackers exploit 32 zero-days on first day of Pwn2Own Ireland

    Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan

    Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

    Social Engineering Detection Moves Into the Live Conversation

    8.8 Million Impacted by Data Breach at Denmark’s Central Person Register

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    I see what’s happening here in Paris: reasonable student demands met with awful violence | Helen Massy-Beresford

    October 7, 2026

    Is Kennedy Center selling its Steinway pianos?

    October 7, 2026

    Russia ‘pursuing strategy of terror’, EU’s von der Leyen says after deadly strikes on Ukraine – Europe live | Europe

    October 7, 2026

    EU-Parlament verschärft vor Šefčovič-Reise Haltung zur China-Politik – POLITICO

    October 7, 2026
    Latest Posts

    4 Best Compression Boots: Therabody, Hyperice, and More (2026)

    August 9, 2026

    Former Iraqi provincial governor arrested as graft crackdown continues | Corruption News

    August 9, 2026

    The culture surrounding ‘ideal’ childbirth has to evolve | Childbirth

    August 9, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    I see what’s happening here in Paris: reasonable student demands met with awful violence | Helen Massy-Beresford

    October 7, 2026

    Is Kennedy Center selling its Steinway pianos?

    October 7, 2026

    Russia ‘pursuing strategy of terror’, EU’s von der Leyen says after deadly strikes on Ukraine – Europe live | Europe

    October 7, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.