Attackers use over 100 hacked sites to spread LunexStealer malware

First reported by The Hacker News at · Updated · 3 sources

Malicious JavaScript inserted into compromised websites presents visitors with fake Cloudflare verification pages. According to Security Affairs, these pages use the ClickFix technique to persuade people to run a command that downloads and installs the malware. Cyber Security News reports that the Windows malware can steal information and accept remote commands.

  • The Hacker News reports that CERT-UA attributed the activity to UAC-0277.
  • LunexStealer is also called Psychedelic Stealer, according to The Hacker News.

Covered by 3 publishers within 7 hours of the first report.

Reporting3

The Hacker News 100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer · info@thehackernews.com (The Hacker News)
Security Affairs CERT-UA: Fake Cloudflare Checks Deliver LunexStealer Malware · Pierluigi Paganini
Cyber Security News Hackers Compromise 100+ Websites With Fake Cloudflare Checks to Spread LUNEXSTEALER · Tushar Subhra Dutta