
Over 100 Hacked Websites Used to Distribute LunexStealer Malware via Fake Cloudflare Security Checks
Breaking NewsHackingMalwareSecurityCERT-UAClickFixLunexStealerUAC-0277CloudflarePhishingCyber Attack
CERT-UA reported that over 100 hacked websites were used to distribute LunexStealer malware through fake Cloudflare security checks. The attack employed the ClickFix technique, where victims were presented with a fraudulent page mimicking Cloudflare's standard bot verification process. The fake page instructed visitors to run a command supposedly to confirm they were not bots, but this command actually downloaded and installed the LunexStealer malware. The threat actor behind this campaign is tracked as UAC-0277.