Fake Cloudflare Scripts Used to Spread LunexStealer Malware
Over 100 compromised websites are delivering LunexStealer through fake Cloudflare verification scripts. Ukrainian CERT-UA attributes the campaign to a threat actor named UAC-0277.
TL;DR
- More than 100 websites were compromised to deliver LunexStealer malware.
- Attackers used fake Cloudflare JavaScript checks to appear legitimate.
- The campaign was tracked by CERT-UA and linked to threat group UAC-0277.
- Websites were injected with malicious scripts without user knowledge.
- Organizations should audit third-party scripts and monitor for anomalies.
A recent wave of cyberattacks has seen over 100 websites compromised to distribute LunexStealer, an information-stealing malware. These sites were injected with deceptive JavaScript posing as Cloudflare verification tools, tricking users into downloading malicious payloads.
The Computer Emergency Response Team of Ukraine (CERT-UA) uncovered this operation in September 2026 and traced it back to a threat actor known as UAC-0277. The use of trusted branding like Cloudflare helps these attacks evade suspicion, making them particularly dangerous for unsuspecting visitors.
How the Attack Works
- Attackers inject malicious JavaScript into legitimate websites.
- Scripts mimic Cloudflare's verification process to gain user trust.
- Visitors unknowingly execute malware when interacting with the fake interface.
- LunexStealer targets sensitive data including credentials and browser information.
Defensive Recommendations
- Regularly audit all third-party scripts running on your website.
- Implement Content Security Policy (CSP) headers to limit script execution.
- Monitor network traffic for unusual outbound connections or file downloads.
- Use subresource integrity (SRI) to verify script authenticity from external sources.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.