LunexStealer malware

LunexStealer Malware Delivered Through Fake Cloudflare Verification Pages

Over 100 websites have been secretly injected with malicious code designed to trick visitors into downloading LunexStealer, an information-stealing malware. The attack exploits a common page-verification process to bypass user suspicion, making it one of the more convincing social engineering tactics seen recently. Understanding how this attack works is essential for anyone who browses the web, particularly those visiting technical or business sites.

LunexStealer: Fake Cloudflare Checks Delivering Malware

What is LunexStealer and how does it spread

LunexStealer, also referred to as Psychedelic Stealer, is an information-stealing malware that harvests sensitive data from infected devices. The malware typically targets login credentials, browser data, cryptocurrency wallet information and personal files. In the campaign documented by Ukraine's Computer Emergency Response Team in September 2026, the malware was distributed through a method that made it appear legitimate: a fake Cloudflare security check.

Cloudflare's real verification system is commonly seen when visiting websites under certain network conditions. By mimicking this familiar interface, attackers created a convincing facade that lowered user defenses. The malicious JavaScript code was injected directly into the HTML of over 100 compromised websites, meaning legitimate sites had been hacked first, then weaponized as distribution points.

How the fake verification page trick works

When a visitor lands on one of the affected websites, they see what appears to be a standard Cloudflare security check. The page displays a loading animation and assures the user that their connection is being verified. Instead of actually validating anything, the page either redirects to a malware download or triggers an automatic download of the LunexStealer executable.

The attack is effective because it exploits user familiarity and trust. Most internet users have encountered legitimate Cloudflare checks before and know to wait for them to complete. By replicating this experience, the attackers bypass the skepticism that might trigger if a site simply offered a direct download. The injected JavaScript is invisible to casual inspection and remains embedded in the site's code even after a page reload.

The threat actor behind the campaign

Ukraine's CERT-UA attributed this activity to a threat cluster designated UAC-0277. While the full identity and history of this group remain unclear, the campaign demonstrates a shift toward more sophisticated distribution tactics. Rather than sending phishing emails or creating malicious domains from scratch, the group compromised legitimate websites and weaponized them. This approach increases the likelihood that users will click the link and visit the site, since it arrives from a trusted domain.

The choice to target multiple websites simultaneously, rather than focusing on one high-value target, suggests the attackers were interested in broad infection rather than surgical precision. This volume-based approach is typical of groups focused on harvesting credentials and personal data for resale or further exploitation.

Why this attack is difficult to detect and prevent

Many users lack the technical knowledge to distinguish a real Cloudflare check from a fake one. Even experienced users can be fooled when the page is well-crafted. Additionally, the malicious code is injected server-side after the initial website load, which means static security scans may miss it. A site can appear clean one day and become infected the next without the website owner's immediate knowledge.

Browser-based security tools sometimes struggle with this vector because the compromise happens at the web server level, not in the user's browser. By the time a user sees the fake Cloudflare page, they have already been directed to the compromised server by what appears to be a legitimate URL in their address bar.

Detection and protection measures

Recognize that Cloudflare's real verification page does not ask you to download anything. A genuine Cloudflare check verifies your connection and then automatically redirects you to the site you requested. If you see a message asking you to download a file, install software or click a button to "verify" yourself, it is almost certainly malicious.

Implement these protective steps:

  1. Keep your browser and operating system fully updated with security patches
  2. Install and maintain reputable antivirus or anti-malware software
  3. Disable automatic downloads in your browser settings or require confirmation before each download
  4. Be cautious about downloading files, especially executable files like .exe, .msi or .app files
  5. Verify website URLs before entering sensitive information, even on pages that appear to be security checks
  6. Consider using browser extensions that block malicious scripts, though these are not foolproof

What to do if you think you have been infected

If you encountered this fake Cloudflare page and believe you may have downloaded the malware, act quickly. Disconnect the affected device from the internet to prevent data exfiltration and communication with attacker servers. If you downloaded and ran the executable, consider the device compromised and change all sensitive passwords from a different, clean device.

For corporate environments, notify your security team immediately. Organizations that discover compromised websites should work with hosting providers and security vendors to remove the malicious JavaScript and restore clean versions of their sites. Notifying affected users, though uncomfortable, allows them to reset passwords and monitor accounts for unauthorized activity.

Key takeaway for browsing safely

LunexStealer's distribution method succeeded because it weaponized user trust in a familiar security interface. The core lesson is that no legitimate website needs to ask you to download files to verify your connection or prove you are human. Real security checks happen invisibly in the background. Staying alert to unusual requests, keeping your software patched and using security software that monitors for known malware signatures significantly reduces your risk of infection. When in doubt, close the page, restart your device and return to the site later through a direct bookmark or known-good search result.

FAQ

What does LunexStealer actually steal from my computer?

LunexStealer is designed to harvest browser credentials, saved passwords, cryptocurrency wallet data, credit card information stored by browsers and sometimes files from specific locations on your drive. Once stolen, this data is sent to attacker-controlled servers for resale or direct misuse.

Can I get infected just by visiting the compromised website without clicking anything?

Simply visiting the site does not automatically execute the malware. You typically need to click the fake verification button or allow a download to occur. However, some advanced malware uses browser exploits to execute without user interaction, so keeping your browser updated is critical.

How do I know if a Cloudflare check is real?

Real Cloudflare checks redirect you automatically after a few seconds without asking you to download anything, enter information or click additional buttons. If the page asks you to do any of these things, close the page and do not proceed.

Should I stop using websites that were compromised?

Not necessarily. Once a website owner discovers the injection, they typically clean and patch the server. Check whether the site has issued a security notice. If you are concerned, contact the website owner directly through their official contact channels to verify the status before returning.

Does antivirus software detect LunexStealer?

Most reputable antivirus programs detect known variants of LunexStealer and similar stealers, but new or heavily modified variants may evade detection. Antivirus is one layer of defense, not a complete solution. Behavioral blocking and not running unknown executables remain your strongest defenses.

Source: The Hacker News