← Back to blog

Fake Cloudflare Scripts Used to Spread LunexStealer Malware

Over 100 compromised websites are delivering LunexStealer through fake Cloudflare verification scripts. Ukrainian CERT-UA attributes the campaign to a threat actor named UAC-0277.

TL;DR

  • More than 100 websites were compromised to deliver LunexStealer malware.
  • Attackers used fake Cloudflare JavaScript checks to appear legitimate.
  • The campaign was tracked by CERT-UA and linked to threat group UAC-0277.
  • Websites were injected with malicious scripts without user knowledge.
  • Organizations should audit third-party scripts and monitor for anomalies.

A recent wave of cyberattacks has seen over 100 websites compromised to distribute LunexStealer, an information-stealing malware. These sites were injected with deceptive JavaScript posing as Cloudflare verification tools, tricking users into downloading malicious payloads.

The Computer Emergency Response Team of Ukraine (CERT-UA) uncovered this operation in September 2026 and traced it back to a threat actor known as UAC-0277. The use of trusted branding like Cloudflare helps these attacks evade suspicion, making them particularly dangerous for unsuspecting visitors.

How the Attack Works

  • Attackers inject malicious JavaScript into legitimate websites.
  • Scripts mimic Cloudflare's verification process to gain user trust.
  • Visitors unknowingly execute malware when interacting with the fake interface.
  • LunexStealer targets sensitive data including credentials and browser information.

Defensive Recommendations

  • Regularly audit all third-party scripts running on your website.
  • Implement Content Security Policy (CSP) headers to limit script execution.
  • Monitor network traffic for unusual outbound connections or file downloads.
  • Use subresource integrity (SRI) to verify script authenticity from external sources.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

Fake Cloudflare Scripts Used to Spread LunexStealer Malware — Agent Breach Blog | Agent Breach