Hackers Use Fake Cloudflare Checks to Deploy LUNEXSTEALER Malware Across Over 100 Sites
Cybercriminals have taken control of more than a hundred online sites, turning ordinary page visits into a delivery mechanism for the Windows‑based trojan known as LUNEXSTEALER. The attackers achieve this by inserting counterfeit Cloudflare verification pages that appear to users as the familiar “checking your browser” prompt, only to redirect traffic to the malicious payload. Security researchers first observed the coordinated effort earlier this month, noting the scale and the deceptive use of a trusted security service’s branding.
LUNEXSTEALER is designed to harvest a range of personal and corporate data from infected machines. Once installed, the malware can capture login credentials, browser cookies, and files stored on the system. In addition, it opens a channel for remote operators to issue commands, enabling actions such as downloading additional tools, exfiltrating data, or deploying ransomware. Its modular architecture makes it adaptable to different victim environments.
The intrusion method relies on compromising the web server or its content‑management system and then serving a forged Cloudflare interstitial page. Visitors to the compromised site are shown a page that mimics Cloudflare’s standard “Checking your browser before accessing” notice, complete with the familiar logo and timing animation. After a brief pause, the page automatically redirects the user to a malicious executable hosted on the attacker’s server, where the LUNEXSTEALER payload is downloaded and run.
Analysts have identified a diverse set of affected domains, ranging from small business storefronts to larger news portals. The common denominator appears to be the use of third‑party plugins or outdated software that provided an entry point for the attackers. By exploiting these weak spots, the criminals were able to inject the counterfeit verification page without alerting the site’s administrators, allowing the campaign to operate unnoticed for weeks.
The ramifications for end users are significant. A successful infection can give threat actors access to sensitive personal information, financial details, and corporate secrets. Because the malware also accepts remote commands, compromised machines can be enlisted in broader botnets or used as footholds for further intrusion into corporate networks. The use of a trusted brand like Cloudflare adds a layer of credibility that may lower users’ suspicion.
Security firms responding to the incident advise site owners to conduct immediate code audits, verify the integrity of all third‑party components, and enforce strict access controls on their servers. Deploying subresource integrity checks and monitoring for unauthorized changes to HTML files can help detect similar tampering. For users, keeping Windows operating systems patched, running reputable anti‑malware solutions, and being cautious of unexpected verification screens are essential defensive steps.
Investigations are ongoing to map the full command‑and‑control infrastructure behind LUNEXSTEALER. Researchers expect that the attackers may repurpose the same technique against additional sites, given the low cost of hijacking the Cloudflare‑style page. The episode underscores the need for continuous security hygiene and the dangers of assuming that familiar security cues are always trustworthy.
Comments (0)
Be the first to comment.
Join the discussion