LunexStealer: 100-plus sites push fake Cloudflare checks
ClickFix MSI lure and malicious browser extension

LunexStealer: 100-plus sites push fake Cloudflare checks

Ukraine's CERT-UA identified more than 100 compromised websites injecting JavaScript that serves LunexStealer, also called Psychedelic Stealer. The cluster is tracked as UAC-0277. Visitors get a forged Cloudflare verification page and are told to prove they are human by running a command. That command downloads a malicious MSI. This is the ClickFix pattern, now paired with a stealer that also takes the browser.

What happened

The injected script does not hard-code its lure. It pulls the loader domain and an operating mode from a smart contract on Polygon or Ethereum, a technique known as EtherHiding. Mode 0 is idle. Mode 1 only tracks visitors. Mode 2 shows the fake check, and only to Windows users who arrived from a search engine, at most twice in 12 hours.

Three MSI variants have been seen. One installs the stealer directly. A second bypasses UAC, adds Microsoft Defender exclusions, and uses a vulnerable signed AMD driver, PDFWKRNL.sys, to blind security tools. A third sideloads a rogue DLL through a legitimate FnHotkeyUtility.exe. The stealer also installs a browser extension posing as Microsoft Office Word Editor, which can steal cookies, history, and form credentials, and can run script in the browser.

Who is affected

Windows users who followed a fake verification prompt on a compromised site, and any organisation whose staff or clients browse from managed endpoints without controls on the Run dialog or MSI installs. CERT-UA did not publish a victim count. The delivery method is aimed at ordinary visitors, not only at administrators.

  • Block the Windows Run dialog for standard users
  • Stop non-admins from installing MSI packages
  • Alert on msiexec.exe launched from a browser or shell one-liner
  • Turn on Microsoft's vulnerable-driver blocklist and the ASR rule that blocks abused signed drivers

What to do now

Treat any user who ran a command from a browser verification page as a probable stealer infection, not a phishing miss. Isolate the endpoint, check for unexpected browser extensions, Defender exclusions, and the AMD driver abuse path, then reset browser-stored credentials and session cookies. On your own sites, scan for injected verification scripts that load configuration from a blockchain contract.

Source: The Hacker News, 7 October 2026, 100-plus compromised websites use fake Cloudflare checks to deliver LunexStealer. CERT-UA advisory: article 6319983.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

CVE-2026-102255: CVSS 10 SSRF in SonicWall SMA1000
SMA1000 WorkPlace unauthenticated server-side request forgery