100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer
- ID
- 32667
- Status
- summarized
- Published
- 07 Oct 2026, 2:57 PM
- Fetched
- 07 Oct 2026, 4:24 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/10/100-compromised-websites-use-fake.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 5.5
- Created
- 07 Oct 2026, 4:24 PM
- Tags
- Audience
- developersvibe_coders
What happened
CERT-UA says it observed in September 2026 more than 100 compromised websites injected with malicious JavaScript that shows a forged Cloudflare 'verify you are human' page and, via the ClickFix technique, tells visitors to execute a command that pulls and installs an MSI delivering LunexStealer (aka Psychedelic Stealer); the cluster is tracked as UAC-0277. The lure is served only to Windows users arriving from search engine results and no more than twice in 12 hours, and the loader domain plus one of three operating modes (0 inactive, 1 passive visitor/page tracking, 2 fake verification page) is fetched from a smart contract on Polygon or Ethereum using EtherHiding. Three MSI variants were found: one installs the stealer directly, one bypasses UAC, adds Microsoft Defender exclusions and abuses the vulnerable AMD driver PDFWKRNL.sys, and one sideloads spkvol.dll through the legitimate FnHotkeyUtility.exe; Arctic Wolf Labs and Ontinue report it also installs a LUNARAXE browser extension. CERT-UA did not name victims or confirm any successful compromises.
Why it matters
This is not a patch-and-move-on CVE, so the decision is behavioural: never paste a command from a browser 'human verification' prompt into Windows Run or a terminal, and treat any machine where someone did as compromised. Because the fake check appears only twice per 12 hours to Windows users coming from search results, re-checking the site and seeing nothing proves nothing, and because the payload domain comes from a Polygon/Ethereum smart contract, blocklisting that domain is not durable. If you suspect exposure, look for Defender exclusions you did not add, spkvol.dll sitting next to FnHotkeyUtility.exe, and the LUNARAXE browser extension. Nothing in this item is Malaysia- or Southeast Asia-specific; it is a global ClickFix campaign with no local angle stated.
Discussion angle
ClickFix targets exactly the reflex this audience has — pasting a command to make something work — so demo how a fake Cloudflare check looks versus the real one, and discuss why the EtherHiding smart-contract lookup makes the usual 'block the domain' response ineffective.