Hackers Compromise 100+ Websites With Fake Cloudflare Checks to Spread LUNEXSTEALER

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Hackers compromised more than 100 websites and used fake Cloudflare verification pages to spread LUNEXSTEALER, a Windows malware capable of stealing information and accepting remote commands.

The campaign turned visits to legitimate websites into opportunities to infect visitors’ computers. The attackers added malicious JavaScript to website pages, making a familiar security check the starting point for infection.

Similar fake Cloudflare verification attacks have used this approach to persuade visitors to run commands rather than download an obviously suspicious attachment. CERT-UA researchers identified the activity in September 2026 and tracked it as UAC-0277.

CERT-UA said in a report shared with Cyber Security News (CSN), published September 30, that its analysts examined three installer variants used to deliver the malware.

The malware can collect saved browser passwords, authentication tokens, cryptocurrency wallet data, and system information.

Its remote execution features extend the risk beyond information theft, allowing attackers to download additional software and issue commands. The advisory does not establish how many visitors were infected.

Hackers Compromise 100+ Websites With Fake Cloudflare Checks

The fake page asked visitors to execute a command to prove they were human. Following that instruction downloaded and installed a Windows MSI package from a remote server. This technique, known as ClickFix, relies on users performing the dangerous action themselves.

The injected script retrieved its operating mode and verification domain from a smart contract on the Polygon or Ethereum network. That arrangement let attackers change the campaign’s destination centrally without returning to each compromised website to edit its code.

Three modes controlled its behavior: inactive, passive visitor tracking, and fake verification display. Passive tracking sent information about the compromised website and the referring page to attacker infrastructure, while the active mode presented the deceptive challenge.

The challenge appeared only to Windows users arriving through search engines, including Google and DuckDuckGo. It was shown no more than twice within 12 hours, making exposure selective rather than displaying the same malicious prompt to every visitor.

Fake Cloudflare verification page (Source - CERT-UA)
Fake Cloudflare verification page (Source – CERT-UA)

One installer deployed LUNEXSTEALER directly. Another used a loader that attempted to bypass Windows User Account Control, added Microsoft Defender exclusions, and exploited CVE-2023-20598 in a vulnerable AMD driver to interfere with security tools.

This mirrors vulnerable Windows driver abuse seen in other attacks, where legitimate but flawed drivers help undermine defenses. A third installer used a legitimate executable to load a malicious library, which decrypted and launched the stealer.

Browser Takeover

Depending on instructions from its control server, LUNEXSTEALER can install LUNARAXE, a malicious extension for Chromium browsers.

The extension disguises itself as an office document editing tool while collecting cookies, browsing history, bookmarks, and credentials entered into website forms.

Its capabilities resemble malicious browser extension backdoors that combine surveillance with remote control. Attackers can manipulate tabs, capture screenshots, change proxy settings, and execute JavaScript on webpages, giving them visibility into browsing activity and control over what victims see.

A supporting PowerShell component, NAIVEMESS, bridges the extension to the Windows file system. Through it, attackers can browse directories, read and write files, and launch them.

Another extension component removes website security policies that restrict scripts and data transfers. The malware communicates with its control server over HTTP, while the extension also supports WebSocket connections for remote interaction.

Its background browser component resumes after a browser restart, and the stealer can create a scheduled task to maintain access on infected systems.

CERT-UA stresses that genuine human verification never requires opening the Windows Run dialog, a command prompt, or PowerShell to paste and execute commands. Users encountering such instructions should close the page, even when the website is familiar.

Administrators should restrict ordinary users’ access to the Run dialog through group policies and limit MSI installation without administrator rights.

CERT-UA also recommends monitoring installer launches containing URLs, enabling Microsoft’s vulnerable driver blocklist, and permitting only approved browser extensions.

Suspected fake verification pages should be reported to CERT-UA. Owners or administrators of compromised websites can contact the team for practical assistance and guidance on determining how attackers gained access.

Indicators of compromise (IoCs):-

Type Indicator Description
IPv4 107[.]175.82.242 Campaign infrastructure listed by CERT-UA.
IPv4 193[.]178.158.61 Campaign infrastructure.
IPv4 193[.]178.159.128 Host appearing in HTTP and remote-extension endpoints.
IPv4 109[.]238.86.112 Campaign infrastructure with a listed HTTP endpoint.
IPv4 109[.]238.86.113 Campaign infrastructure with a listed HTTP endpoint.
IPv4 176[.]53.159.40 Campaign infrastructure.
IPv4 159[.]69.234.218 Campaign infrastructure.
Domain ahahahahadebili[.]help Domain appearing in script and installer URLs.
Domain fsputnik[.]com Campaign domain.
Domain sputnk[.]com Domain appearing in an installer URL.
Domain uasputnik[.]com Domain appearing in multiple installer URLs.
Domain uasputn[.]com Domain appearing in an installer URL.
Domain partaonline[.]click Campaign domain.
Domain vibestglobal[.]com Campaign domain.
Domain flareru[.]live Campaign domain.
Domain plerdgate[.]com Campaign domain.
Domain ukrainerada[.]top Domain appearing in a script URL.
Domain radaukraine[.]top Campaign domain.
Domain astratechuthree[.]top Campaign domain.
Domain spectre.pp[.]ua Domain appearing in script and installer URLs.
Domain chillplace.pp[.]ua Domain appearing in a script URL.
Domain alohapages.pp[.]ua Domain appearing in a script URL.
Domain vatra.pp[.]ua Campaign domain.
Domain fainomedia.pp[.]ua Campaign domain.
Domain trembita.pp[.]ua Campaign domain.
Domain archivision.pp[.]ua Campaign domain.
WebSocket endpoint (ws)://193[.]178.159.128:8080/api/v1/ext/remote Remote-extension endpoint, preserving the source’s notation.
URL hXXp://107[.]175.82.242:9000/wilow/psychedeliclove[.]exe Executable download location.
URL hXXp://193[.]178.159.128:8080 Listed HTTP endpoint.
URL hXXps://uasputnik[.]com/elit.msi MSI download location.
URL hXXps://uasputnik[.]com/elita.msi MSI download location.
URL hXXps://uasputnik[.]com/elite.msi MSI download location.
URL hXXp://109[.]238.86.112:8080 Listed HTTP endpoint.
URL hXXp://109[.]238.86.113:8080 Listed HTTP endpoint.
URL hXXps://ahahahahadebili[.]help/tds/tds.php Campaign script endpoint.
URL hXXps://ahahahahadebili[.]help/think.msi MSI download location.
URL hXXps://sputnk[.]com/think.msi MSI download location.
URL hXXps://uasputn[.]com/esptnk.msi MSI download location.
URL hXXps://uasputnik[.]com/omen.msi MSI download location.
URL hXXps://ukrainerada[.]top/tds/tds.php Campaign script endpoint.
URL hXXps://chillplace.pp[.]ua/tds/tds.php Campaign script endpoint.
URL hXXps://alohapages.pp[.]ua/tds/tds.php Campaign script endpoint.
URL hXXps://spectre.pp[.]ua/tds/tds.php Campaign script endpoint.
URL hXXps://spectre.pp[.]ua/spectre.msi MSI download location.
URL https[:]//ilovecutecatetetes[.]click Additional URL listed by CERT-UA.
URL https[:]//ilovecutecatics[.]com Additional URL listed by CERT-UA.
URL fragment htt [ ]//il t ti [ ] [ ]8080 Final URL is clipped in the supplied PDF; this is its extracted fragment, not a usable or reconstructed indicator.
File PDFWKRNL.sys Vulnerable AMD driver identified in the infection chain.
File FnHotkeyUtility.exe Legitimate executable abused for malicious DLL loading; not inherently malicious.
File spkvol.dll Malicious library used to decrypt and launch LUNEXSTEALER.
File msiexec.exe Legitimate Windows installer process CERT-UA recommends monitoring for URL-bearing command lines.
Scheduled task psychedelicloveUtils Configurable persistence task.
Native-messaging host com.lunex.explorer Host registration used by NAIVEMESS.
Extension display name Microsoft Office Word Editor Deceptive name used by LUNARAXE.
MD5 / SHA-256 1f250eb486571d99bc1e4d760e37a554
38e90affe37342ee36917cdc535fe9bf04589afa8430eb8d1ba1016adcfc1878
Filename shown as elita.; clipped in the PDF.
MD5 / SHA-256 348cabe85c8bb40e690ab873ab94acac
bf14cd6c3328ebd08e940478b5d1da04e9e5aa576d045d41950bf4f1e2456dd8
psychedelic.exe.
MD5 / SHA-256 b96d75a000367c200958089728fc5cb8
6e8b49cf70bf854e8c59c7d27cefa89406caf8978461190dabb86dafcd8554e1
embedded_driver.sys.
MD5 / SHA-256 670086be6d64b3fc9d9edcbaf8986c02
3b039a36ed576353cb7eb1054b6ac56f42f63a6fc447edeb58c48b4bb7537482
Filename shown as elit.m; clipped in the PDF.
MD5 / SHA-256 dac640a37d5096c47fdd8f745b9a9115
2a373c2ace484d2ada44a26b356de18b5ec8e9d57c5060d42ff239ec1705059c
Progressive.exe.
MD5 / SHA-256 d8a99b7a81cfdacc8734e098efe8076e
ad858ea577379fe1ab9e566b2108302185527c66eb9cbd7d0e381297316e8881
Filename shown as spkvol; clipped in the PDF.
MD5 / SHA-256 ae5450f32bcb533c5b592c77a7861553
06f434695f93d7fd11eeff71358ff69fed79d310a66d993bbcc4ff979c117c90
psychedeliclove.exe.
MD5 / SHA-256 081eba2bfe3bfb56d6c5ad7d1b28fd6c
cbe90746b6c6f0e4c0e80d4748a149f85341f8405b9e524f8abcf0723a97438b
Filename shown as elite.; clipped, first sample.
MD5 / SHA-256 f45a2b3995b2da034b2e03b7ed6cdaaa
f145d4f731d4140de183473b5c6a500a31f44173153fd323cadafa334ee83a3d
Filename shown as elite.; clipped, second sample.
MD5 / SHA-256 86f5a4f1e83e8b9db390736539863e91
eed67d92d1f059e5b848114c0846207db357d1d60b494b88b8f0e3d9ba5cf24a
Filename shown as think.; clipped in the PDF.
MD5 / SHA-256 cb18caf0dd576a356bb0627989f85b8c
c2198398e84684d7b48d92261996116d2d98c7d4ffbff2b8cc955d1ff06e77eb
thinking_12.9.84.30_INSTALL.exe; an additional filename fragment, fr, is clipped.
MD5 / SHA-256 b7081d752375ad8b06639cc9506a4e8e
f16ed095c92c5f65ddb43bf4a6352da1deaead4e98d7187c4fc44d17dfbe88ad
Filename shown as spkvol; clipped in the PDF.
MD5 / SHA-256 19911b5ad1a5952bf17ecff467b45c62
0eb2c2ac3c593bbeef72dff02a38cdba18589b1dc65f3fd730ed33e9e99cb8b7
background.ts-Dgde4GDq.js.
MD5 / SHA-256 9a5d0e4382efec512737fdecb8a71dd8
274dc91b92bf17a05ff4f3bfae04924167e4d53f276e7b6c0d6026b3304827b0
content.ts-B6XGI__y.js, first sample.
MD5 / SHA-256 eac6683cb79f2e3bd570ee9edd077f3b
6b6a30712d566d30a20c6232d2fe9bc1c49170d78d1ab548513ab46f86bf3c06
Filename fragments serv and worker-loader.js; clipped, first sample.
MD5 / SHA-256 e5a52ed35bece9bf020b891e47317787
1eb51ef2544ce57dfdfafd3b1400e43abb244887b14c82d0c5a984af70152838
manifest.json, first sample.
MD5 / SHA-256 e69a8798fe7d92cee5f7b5321866f01e
725c1cb7ca5f669574988069a3cdb617cba891d4a4a03aa9a1fd3f95c6035997
strip.ts-DrI45pKU.js, first sample.
MD5 / SHA-256 0b05147f194274070073c8768684cea5
4efef6a50ae74ea49283a7aec1ee2014ce15a17c05ac0c8df082a6f1449781fa
Filename shown as esptnk; clipped in the PDF.
MD5 / SHA-256 3408ae0d10986ea2c50dca523667ac47
4cd6b9a5841aabb060f10d4d029d1c10a69ad6d2d9291243c504977cf715fefb
solution_6.81.6017.2_INSTALL.exe.
MD5 / SHA-256 b705a55c963c4c624bfd5d67c6c25fbb
c4e6cfad25e0a93b8542c6280d6c5e0b9de2cfe18c9a67f2d6e4570ae2b92fef
Filename shown as spkvol; clipped in the PDF.
MD5 / SHA-256 ccaa01de34fad977420179382f37bc3e
289e408e1d2661f55e59611535a156914cd7c60f69f6e3de1163c01c56e487d2
background.ts-L_QBuUJg.js.
MD5 / SHA-256 f145ec4608878fcbe5b4c94e510b453c
09f83b5f79b934e12f8077b2b462d938ea8124e15ea0debeefe22b706d6c1e92
content.ts-B6XGI__y.js, second sample.
MD5 / SHA-256 d8ac71c0593997a5d95276bf705ec7e3
299617dd8b220a49dfaa0cbd0c997e9ba8b01d4cfb0f7aada5db923403dc0587
Filename fragments serv and worker-loader.js; clipped, second sample.
MD5 / SHA-256 e3ccdf43a405127c7f1eadce436fccd7
3c9bef5c766c8c0bcc403248a489e656f4e31bea0083575dc815afe68f6abe26
manifest.json, second sample.
MD5 / SHA-256 502eb1fb70c0153f0d56f12d49a20094
957776ef93ff598bfbe9dfba8c80425c1718927605c42e26131b0362dd790343
strip.ts-DrI45pKU.js, second sample.
MD5 / SHA-256 2b19559333c0a5047892cf7239b9057d
fd80d52c7aa4f82744fb6a82c878851a6dd50e001bfbb2b7dd9df884dbcdfb40
Filename shown as omen.m; clipped in the PDF.
MD5 / SHA-256 9fb1c651405f35c859fc89ff4c142a49
b862fa82eacf4b989c6a82155c1f4ab0b435f57b4d20a0bf2871fc675fca6059
Filename shown as omen.e; clipped in the PDF.
MD5 / SHA-256 51ccf7074c6d4753e4a1d335184c39d4
c67c0800d9cff00b0b377e205e03ff4dcb5a6587cceacb4e7b08e29c51aeee9f
Filename shown as spkvol; clipped in the PDF.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post Hackers Compromise 100+ Websites With Fake Cloudflare Checks to Spread LUNEXSTEALER appeared first on Cyber Security News.