hacker-news · Crawled Oct 7, 2026

100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer

3 IoCs
Read original article ↗

AI Summary

Over 100 compromised websites have been injected with malicious JavaScript that displays a fake Cloudflare verification page to deliver LunexStealer, an information-stealing malware. The attack, attributed to threat cluster UAC-0277, uses social engineering via the 'ClickFix' technique to trick users into executing a malicious MSI package. The malware installs a malicious browser extension called LUNARAXE, which steals credentials and browsing data, and deploys an auxiliary component NAIVEMESS for file system access via PowerShell. The campaign uses Ethereum-based smart contracts (EtherHiding) to control script behavior and target Windows users arriving from search engines.

AI-extracted · verify before operational use

Indicators of Compromise 3 extracted

Type Value Detail
Filename spkvol.dll Details →
Filename FnHotkeyUtility.exe Details →
Filename PDFWKRNL.sys Details →