Attackers use over 100 hacked sites to spread LunexStealer malware
Malicious JavaScript inserted into compromised websites presents visitors with fake Cloudflare verification pages. According to Security Affairs, these pages use the ClickFix technique to persuade people to run a command that downloads and installs the malware. Cyber Security News reports that the Windows malware can steal information and accept remote commands.
- The Hacker News reports that CERT-UA attributed the activity to UAC-0277.
- LunexStealer is also called Psychedelic Stealer, according to The Hacker News.
Covered by 3 publishers within 7 hours of the first report.
Reporting3
The Hacker News 100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer · info@thehackernews.com (The Hacker News)
Security Affairs CERT-UA: Fake Cloudflare Checks Deliver LunexStealer Malware · Pierluigi Paganini
Cyber Security News Hackers Compromise 100+ Websites With Fake Cloudflare Checks to Spread LUNEXSTEALER · Tushar Subhra Dutta