Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit Websites with Fake Cloudflare Pages

Hackers Exploit Websites with Fake Cloudflare Pages

Posted on October 7, 2026 By CWS

In a recent cyber attack, hackers infiltrated over 100 websites by deploying counterfeit Cloudflare verification pages. This scheme was used to disseminate LUNEXSTEALER, a Windows malware known for its ability to extract sensitive information and execute remote commands.

How Hackers Compromised the Websites

The attackers turned genuine website visits into opportunities for infection by embedding harmful JavaScript onto site pages. This made the familiar security verification process a gateway for malware installation. Previous attacks have similarly exploited fake Cloudflare verifications to convince users to execute commands rather than download suspicious files.

Implications of the LUNEXSTEALER Malware

Research by CERT-UA, published on September 30, reveals that the malware harvests credentials from web browsers, authentication tokens, and cryptocurrency information. Beyond information theft, it allows attackers to install additional software and issue commands remotely. The report, however, does not specify the number of infected visitors.

Technical Details and Preventive Measures

The fake verification pages prompted users to enter commands under the guise of proving their human identity. This action downloaded a Windows MSI package from a remote server, a technique called ClickFix. The attack targeted Windows users via search engines, ensuring selective exposure.

The injected script utilized a smart contract on the Polygon or Ethereum network to modify the campaign’s destination without altering each compromised site. The malware’s abilities include installing LUNARAXE, a harmful browser extension masquerading as a document editing tool. This extension can collect user data, manipulate browser settings, and allow remote control by attackers.

To mitigate risks, CERT-UA advises that real verification processes never require executing commands in command prompts or PowerShell. Users should exit such sites immediately. Administrators are encouraged to enforce restrictions on MSI installations and monitor installer launches.

Any suspected fake verification pages should be reported to CERT-UA for investigation. Website owners can reach out to CERT-UA for assistance in identifying and rectifying breaches.

As cyber threats evolve, maintaining vigilance and implementing robust security protocols are essential to safeguarding digital environments.

Cyber Security News Tags:browser security, CERT-UA, Cloudflare, Cybersecurity, Hackers, information theft, internet safety, LunexStealer, Malware, remote commands

Post navigation

Previous Post: Critical Atlassian Flaw Poses Risk to Jira Admin Access

Related Posts

HazyBeacon Exploits AWS Lambda for Covert Cyber Operations HazyBeacon Exploits AWS Lambda for Covert Cyber Operations Cyber Security News
Emerging Cyber Threats Featuring QR Codes ClickFix and LOLBins Challenging SOC Defenses Emerging Cyber Threats Featuring QR Codes ClickFix and LOLBins Challenging SOC Defenses Cyber Security News
5 Best IT Infrastructure Modernisation Services In 2025 5 Best IT Infrastructure Modernisation Services In 2025 Cyber Security News
Microsoft Defender for Office 365 to Block Email Bombing Attacks Microsoft Defender for Office 365 to Block Email Bombing Attacks Cyber Security News
Claude AI Flaws Risk Data Theft and Unsafe Redirects Claude AI Flaws Risk Data Theft and Unsafe Redirects Cyber Security News
Nginx 1.29.8 & FreeNginx Update Bolster Security Nginx 1.29.8 & FreeNginx Update Bolster Security Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit Websites with Fake Cloudflare Pages
  • Critical Atlassian Flaw Poses Risk to Jira Admin Access
  • Data Breach at South Korean Churches Exposes Over 1 Million Records
  • Key Challenges Facing US SOCs: Solutions to Improve Efficiency
  • SonicWall Fixes Critical SSRF Vulnerability in SMA1000

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit Websites with Fake Cloudflare Pages
  • Critical Atlassian Flaw Poses Risk to Jira Admin Access
  • Data Breach at South Korean Churches Exposes Over 1 Million Records
  • Key Challenges Facing US SOCs: Solutions to Improve Efficiency
  • SonicWall Fixes Critical SSRF Vulnerability in SMA1000

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark