Home / Oct 08, 2026 / Story
0
#8 The Hacker News general October 07, 2026 at 06:57 UTC

100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer

By [email protected] (The Hacker News)

AI Summary

CERT-UA identified over 100 compromised Ukrainian websites injected with malicious JavaScript serving LunexStealer (also known as Psychedelic Stealer), in a ClickFix-style campaign that uses fake Cloudflare verification pages. The activity, observed in September 2026, has been attributed to threat cluster UAC-0277. The technique of abusing trusted infrastructure prompts to deliver infostealers continues to evolve, making it difficult for end users to distinguish legitimate browser security checks from malicious ones.

Relevance score: 74.0/100

# More from October 08