In a recent cyber attack, hackers infiltrated over 100 websites by deploying counterfeit Cloudflare verification pages. This scheme was used to disseminate LUNEXSTEALER, a Windows malware known for its ability to extract sensitive information and execute remote commands.
How Hackers Compromised the Websites
The attackers turned genuine website visits into opportunities for infection by embedding harmful JavaScript onto site pages. This made the familiar security verification process a gateway for malware installation. Previous attacks have similarly exploited fake Cloudflare verifications to convince users to execute commands rather than download suspicious files.
Implications of the LUNEXSTEALER Malware
Research by CERT-UA, published on September 30, reveals that the malware harvests credentials from web browsers, authentication tokens, and cryptocurrency information. Beyond information theft, it allows attackers to install additional software and issue commands remotely. The report, however, does not specify the number of infected visitors.
Technical Details and Preventive Measures
The fake verification pages prompted users to enter commands under the guise of proving their human identity. This action downloaded a Windows MSI package from a remote server, a technique called ClickFix. The attack targeted Windows users via search engines, ensuring selective exposure.
The injected script utilized a smart contract on the Polygon or Ethereum network to modify the campaign’s destination without altering each compromised site. The malware’s abilities include installing LUNARAXE, a harmful browser extension masquerading as a document editing tool. This extension can collect user data, manipulate browser settings, and allow remote control by attackers.
To mitigate risks, CERT-UA advises that real verification processes never require executing commands in command prompts or PowerShell. Users should exit such sites immediately. Administrators are encouraged to enforce restrictions on MSI installations and monitor installer launches.
Any suspected fake verification pages should be reported to CERT-UA for investigation. Website owners can reach out to CERT-UA for assistance in identifying and rectifying breaches.
As cyber threats evolve, maintaining vigilance and implementing robust security protocols are essential to safeguarding digital environments.
