UAC-0277 Compromises 100+ Websites to Spread LunexStealer via Fake Cloudflare Checks

The Computer Emergency Response Team of Ukraine (CERT-UA) has uncovered a widespread campaign in which more than 100 legitimate websites were compromised to deliver an information-stealing malware known as LunexStealer (also tracked as Psychedelic Stealer). The activity, observed throughout September 2026, has been attributed to a threat cluster designated UAC-0277.

According to CERT-UA, attackers injected malicious JavaScript into vulnerable sites. When a visitor lands on one of these pages, the script displays a fake Cloudflare "Verify you are human" check. Users who interact with it are prompted to run a malicious command, which ultimately installs LunexStealer on their systems.

How the Infection Chain Works

The attack begins with the compromise of a legitimate website, often through vulnerabilities in content management systems, plugins, or exposed administrative interfaces. Once inside, the attackers insert a snippet of JavaScript that mimics a Cloudflare challenge page. This fake check is designed to lower the victim's guard by leveraging the trust associated with Cloudflare's ubiquitous security service.

When a user clicks the fake verification button, the script copies a malicious PowerShell command to the clipboard and instructs the user to paste it into the Windows Run dialog (Win+R). Executing the command downloads and runs the LunexStealer payload. This technique, sometimes called "ClickFix" or "paste-and-run," bypasses traditional browser security warnings because the final execution step is performed manually by the victim.

What LunexStealer Steals

LunexStealer is a commodity information stealer that targets a wide range of sensitive data on infected machines. It typically harvests:

  • Saved credentials from web browsers (Chrome, Edge, Firefox)
  • Cookies and session tokens
  • Cryptocurrency wallet data
  • FTP and email client credentials
  • System information and files matching specific patterns

The stolen data is then exfiltrated to command-and-control servers controlled by the attackers. Because the malware is often sold or shared on underground forums, it can be used by multiple cybercriminal groups.

Attribution and Scope

CERT-UA attributes the campaign to UAC-0277, a cluster that has been active in previous operations. The agency did not disclose the identity or motivation of the actors behind UAC-0277, but the use of a widely available stealer suggests a financially motivated operation. The 100+ compromised websites span various industries and regions, indicating a broad, opportunistic targeting strategy rather than a focused spear-phishing campaign.

The fact that the malicious scripts were hosted on legitimate sites makes detection more difficult. Security tools that rely on domain reputation may not flag the initial compromise, and users are more likely to trust a verification prompt on a site they already visit.

Why the Fake Cloudflare Check Is Effective

Cloudflare's "Verify you are human" challenge is a familiar sight for many internet users. By replicating this interface, attackers exploit that familiarity. The fake page often includes Cloudflare branding, a checkbox, and even a progress indicator. The instruction to paste a command into the Run dialog is framed as a necessary step to complete the verification, which many users follow without suspicion.

This social engineering tactic has become increasingly popular because it bypasses browser sandboxes and endpoint detection that might block direct drive-by downloads. It also allows attackers to deliver different payloads depending on the victim's operating system or geographic location.

Mitigation and Recommendations

CERT-UA and other security experts recommend the following measures to reduce the risk:

  • Never paste commands from a website into the Run dialog or terminal. Legitimate verification systems do not require this.
  • Keep CMS platforms, plugins, and themes up to date to prevent website compromise.
  • Use endpoint detection and response (EDR) tools that can flag suspicious PowerShell execution and clipboard abuse.
  • Educate users about fake CAPTCHA and Cloudflare checks, emphasizing that no legitimate service will ask them to run a command.
  • Monitor for unusual outbound traffic from endpoints, especially connections to newly registered domains.
  • Implement application allowlisting to prevent unauthorized executables from running.

Website owners should also regularly scan for injected JavaScript, monitor file integrity, and apply security patches promptly. A web application firewall (WAF) can help block common exploitation attempts, though it is not a substitute for proper patch management.

The Bigger Picture

The UAC-0277 campaign is part of a broader trend of using compromised legitimate websites as malware delivery vectors. By piggybacking on trusted domains, attackers evade blocklists and lend an air of legitimacy to their lures. The fake Cloudflare check is just one of many social engineering templates in use; similar campaigns have impersonated Google reCAPTCHA, browser updates, and even error pages.

As information stealers like LunexStealer continue to evolve, organizations and individuals must remain vigilant. The combination of website compromise, social engineering, and living-off-the-land techniques makes this threat particularly challenging to detect and block.

For more details, refer to the original report from The Hacker News: 100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer.