Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Fake Cloudflare Verification Pages Used to Push LUNEXSTEALER Malware on 100+ Hacked Sites
Fake Cloudflare Verification Pages Used to Push LUNEXSTEALER Malware on 100+ Hacked Sites
Read Time:3 Minute, 31 Second

Ukraine’s national cyber incident response team, CERT-UA, published findings on September 30, 2026 describing a campaign that has already compromised more than 100 legitimate websites to serve a convincing fake of Cloudflare’s familiar “verify you are human” check. The agency tracks the activity as UAC-0277. Rather than exploiting a technical flaw in visitors’ browsers, the campaign relies on a social-engineering trick known as ClickFix, which hands attackers the one thing no browser sandbox can stop: the victim’s own willingness to run a command they were told would prove they’re not a bot.

A Verification Prompt Built to Fool, Not Verify

Visitors who land on one of the compromised sites — CERT-UA says many arrive after searching on Google or DuckDuckGo — are shown the fake check only if they’re on Windows, and never more than twice within a 12-hour window, a limitation that likely helps the campaign stay under the radar of casual observers and automated scanners alike. Instead of running a real CAPTCHA, the page instructs the visitor to open the Windows Run dialog and paste in a command to “prove” they’re human. That single action downloads and silently installs a Windows MSI package pulled from attacker-controlled infrastructure.

The injected code on each hacked site doesn’t hardcode where that MSI comes from. Instead, it reads its operating mode and target domain from a smart contract deployed on the Polygon or Ethereum blockchain — letting the operators redirect every compromised site to new infrastructure from one central place, without having to touch the injected script on any individual victim site. CERT-UA found the script can run in three distinct modes: dormant, quietly logging which site and referring page a visitor came from, or actively displaying the fake verification page.

Three Ways In, One Stealer at the End

Researchers examined three separate installer variants used across the campaign. One drops the LUNEXSTEALER payload directly. A second is more aggressive: it attempts to bypass Windows User Account Control, adds exclusions to Microsoft Defender, and exploits a known flaw (CVE-2023-20598) in a legitimate but vulnerable AMD driver to interfere with security tooling before the stealer runs. A third variant sideloads a malicious DLL through a legitimate utility executable, which then decrypts and launches the stealer in memory. All three establish persistence through a background component that automatically relaunches after reboot, backed by a scheduled task.

What LUNEXSTEALER Actually Takes

Once installed, LUNEXSTEALER harvests saved browser passwords, authentication tokens, cryptocurrency wallet files, and general system information, and it can receive further commands or download additional tools over HTTP and WebSocket connections to attacker infrastructure. On command, it can go a step further and install a companion browser extension, tracked as LUNARAXE, disguised as an innocuous “Microsoft Office Word Editor” add-on. That extension can read cookies, browsing history, bookmarks, and anything typed into web forms, and it’s capable of manipulating open tabs, taking screenshots, altering proxy settings, and executing arbitrary JavaScript on pages the victim visits. A PowerShell component CERT-UA calls NAIVEMESS bridges the extension to the underlying file system, letting it browse, read, write, and launch files, while another module strips security policies from visited pages to make data exfiltration easier.

What Defenders Should Do

CERT-UA’s guidance is refreshingly simple and worth repeating to any user: genuine identity or human verification never requires opening the Run dialog, Command Prompt, or PowerShell — full stop. Any page that asks for this should be closed immediately, even on a site the visitor trusts. Organizations can get ahead of the technique with group policy restrictions on the Run dialog for ordinary users, limits on who can install MSI packages without administrative rights, monitoring for installer processes whose command lines contain URLs, Microsoft’s vulnerable driver blocklist enabled, and an allowlist restricting which browser extensions employees can install. CERT-UA is also asking owners of any compromised website to report the incident so investigators can trace how attackers gained write access to the site in the first place — which, for website operators, is really the other half of this story: being used to distribute LUNEXSTEALER means a site’s own CMS or hosting credentials were compromised well before any visitor ever saw the fake prompt.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Fake Cloudflare Verification Pages Used to Push LUNEXSTEALER Malware on 100+ Hacked Sites, use the discussion on Forum.

>> forum community

Comments

Leave a Reply