Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Over 100 Sites Compromised Using Fake Cloudflare Checks

Over 100 Sites Compromised Using Fake Cloudflare Checks

Posted on October 7, 2026 By CWS

The Computer Emergency Response Team of Ukraine (CERT-UA) has revealed a new cybersecurity threat affecting over 100 websites. These sites have been infiltrated with harmful JavaScript code designed to deploy an information-stealing malware known as LunexStealer, also referred to as Psychedelic Stealer.

Discovery of Malicious Activity

In September 2026, CERT-UA identified this malicious activity, attributing it to a group known as UAC-0277. However, details about the specific individuals or systems targeted remain undisclosed. The attackers utilized counterfeit Cloudflare verification pages to deceive users into executing commands that install malware.

The fraudulent verification pages, appearing genuine, prompt users to download and run a harmful MSI package via the ClickFix technique. This method disguises the malware as a legitimate security check, tricking unsuspecting visitors into compromising their systems.

Techniques and Variants Used

Attackers employed the EtherHiding technique to obscure the origin of the malicious scripts, using smart contracts on blockchain networks like Polygon and Ethereum. The campaign operates in three distinct modes: inactive, passive data collection, and active malware deployment.

The active deployment, or Mode 2, targets Windows users who access these compromised sites through search engine results, limiting exposure to twice within 12 hours. The attackers utilized three MSI package variants, each with unique methods for installing LunexStealer and evading security measures.

Impact and Mitigation Strategies

LunexStealer is designed to install a fraudulent browser extension named LUNARAXE, which poses as a legitimate Microsoft Office tool. This extension captures sensitive data like cookies and credentials, providing attackers with remote browser control.

Additionally, an auxiliary component called NAIVEMESS facilitates file system access, enhancing LUNARAXE’s capabilities. CERT-UA advises organizations to implement security measures such as restricting MSI package installations and monitoring for unauthorized software executions.

Microsoft further recommends enabling specific security policies, like the Attack Surface Reduction (ASR) rule, to prevent the installation of vulnerable drivers that could be exploited by such threats.

Organizations are urged to strengthen their cybersecurity protocols to combat these sophisticated threats effectively. Continuous monitoring and updating of security systems are crucial steps in safeguarding against such pervasive malware campaigns.

The Hacker News Tags:browser security, C2 Server, CERT-UA, Cloudflare, Cybersecurity, JavaScript, LUNARAXE, LunexStealer, Malware, Microsoft Defender, MSI packages, NAIVEMESS, UAC-0277, vulnerable drivers, web security

Post navigation

Previous Post: Anthropic Expands Access to Claude for Cybersecurity Experts
Next Post: Wikimedia Identifies Unauthorized OpenAI Agent Activities

Related Posts

Microsoft Resolves Record 974 Vulnerabilities in September Microsoft Resolves Record 974 Vulnerabilities in September The Hacker News
Kickstart Your Intelligent Workflow Program with 3 Key Strategies Kickstart Your Intelligent Workflow Program with 3 Key Strategies The Hacker News
Critical Open VSX Bug Fixed in VS Code Extension Security Critical Open VSX Bug Fixed in VS Code Extension Security The Hacker News
Chrome Users Urged to Update Amid V8 Security Flaw Chrome Users Urged to Update Amid V8 Security Flaw The Hacker News
North Korean Hackers Use Facebook to Spread Malware North Korean Hackers Use Facebook to Spread Malware The Hacker News
OpenAI Introduces GPT-5.6-Cyber for Advanced Cybersecurity OpenAI Introduces GPT-5.6-Cyber for Advanced Cybersecurity The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Google Chrome Update Patches 247 Security Vulnerabilities
  • Critical Atlassian Vulnerability Fixed Across Key Products
  • 32 Zero-Day Vulnerabilities Exploited at Pwn2Own 2026
  • Wikimedia Identifies Unauthorized OpenAI Agent Activities
  • Over 100 Sites Compromised Using Fake Cloudflare Checks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Google Chrome Update Patches 247 Security Vulnerabilities
  • Critical Atlassian Vulnerability Fixed Across Key Products
  • 32 Zero-Day Vulnerabilities Exploited at Pwn2Own 2026
  • Wikimedia Identifies Unauthorized OpenAI Agent Activities
  • Over 100 Sites Compromised Using Fake Cloudflare Checks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark