LunexStealer malware

How LunexStealer Exploits Fake Cloudflare Checks to Steal Data

Over 100 websites have been compromised to inject a malware loader disguised as a Cloudflare security check. The malicious JavaScript redirects visitors to a fake verification page, harvests their credentials, and downloads LunexStealer (also called Psychedelic Stealer) onto their machines. This attack chain is deceptively simple because it exploits trust in a legitimate service that users encounter regularly.

LunexStealer: Fake Cloudflare Checks on Hacked Sites

What Is LunexStealer and Why It Matters

LunexStealer is an information-stealing malware known by multiple names in the threat research community, including Psychedelic Stealer. Security analysts classify it as a data-harvesting tool designed to extract credentials, browser cookies, autofill data and local files from infected machines. The malware became notable because it was deployed not through email or direct downloads, but through a supply-chain compromise: attackers gained access to legitimate websites and modified their code to redirect visitors to a fake Cloudflare security check before downloading the stealer payload.

Why this matters to ordinary users is straightforward. Many websites use Cloudflare as a content delivery and security service, so users see their verification pages regularly and have learned to expect them. Attackers exploited this trust by creating counterfeit checks that look identical to the real thing. When someone lands on one of the compromised sites, they are prompted to "verify" themselves, unknowingly hand over their credentials or cookies, and then receive a file download without realizing they have been infected.

How the Attack Chain Works

The mechanics of the LunexStealer infection begin with server-side compromise. Threat actors, in this case attributed to a group called UAC-0277, gained unauthorized access to over 100 websites. Rather than deface them visibly or steal data directly, they injected malicious JavaScript code that runs invisibly to site visitors. This code watches for traffic and, under certain conditions or for certain users, redirects the browser to a fake Cloudflare challenge page.

The fake page mimics Cloudflare's genuine security interface so closely that most users cannot tell the difference. The page typically asks visitors to verify their identity by entering their browser credentials, email login or other sensitive information. Once the user submits the form, the stolen data is logged by the attackers. The page then redirects back to the legitimate site or displays a fake "verification complete" message, and simultaneously triggers a file download. The downloaded file contains the LunexStealer loader, which executes with minimal fanfare and begins harvesting data from the victim's machine.

The Real-World Impact on Users and Websites

Victims of this attack lose control of their credentials and browsing data almost immediately. LunexStealer typically targets password managers, browser autofill databases, session cookies for email and banking services, and cached authentication tokens. Attackers can then use these credentials to access the victim's email, bank account, cryptocurrency exchange login or SaaS applications without needing to crack any passwords. The damage extends beyond a single website visit; it persists as long as the malware runs and is not detected and removed.

Website owners face a serious reputation and liability problem. Users who land on a compromised site and become infected may never know which website was responsible. This attack pattern also undermines trust in legitimate security services like Cloudflare, because the phishing pages look so convincing that some users become skeptical of real Cloudflare checks. Website administrators must not only regain control of their servers but also notify users that their site was weaponized without their knowledge or consent.

Why Fake Cloudflare Checks Work So Well

Cloudflare verification pages have become normalized in user experience. Millions of sites use Cloudflare as their first layer of defense, and users see challenge pages regularly when accessing sites from new IP addresses or on congested networks. This frequency has created what security researchers call "security habituation," where users stop scrutinizing the page carefully and simply fill in what is asked of them. Attackers exploit this psychology by creating near-perfect replicas of the real interface, including the Cloudflare logo, the correct styling and even the same URL structure in the address bar (through domain spoofing or subdomains that look similar at first glance).

Another factor is that Cloudflare itself is trusted because it genuinely does verify users, block bots and protect websites. When a user sees the page, they assume the website owner has configured Cloudflare protection and comply with the request. The attacker has essentially borrowed the credibility of Cloudflare's entire service to lower the victim's guard.

How to Recognize and Avoid These Attacks

Protecting yourself begins with developing a habit of verification before entering credentials into any security check.

  1. Check the URL carefully: a real Cloudflare check will come from a Cloudflare-owned domain or a subdomain of the site you are visiting. If the URL looks unusual, contains a typo or differs from what you expect, do not proceed.
  2. Look at the certificate: right-click on the page and select "inspect" or "view page info." Check the SSL certificate owner. If it is not issued to Cloudflare or the website you are visiting, the page is fake.
  3. Verify through a different channel: if you are unsure, close the page and visit the website directly from a bookmark or by typing the domain name fresh in the address bar. If you can reach the site normally without a challenge, you were likely on a phishing copy.
  4. Use a security browser extension: tools like uBlock Origin or similar content blockers can help catch suspicious redirects and JavaScript injections, though they are not foolproof.
  5. Never enter passwords into unexpected security checks: legitimate services rarely ask you to re-enter your password in a verification page. If prompted, close the page and contact the website's support team through an official channel.

Companies and website administrators should implement Content Security Policy (CSP) headers, regular server audits, Web Application Firewalls (WAF) and file integrity monitoring to detect unauthorized JavaScript injections early. Users on these sites benefit from faster detection of compromises, which reduces the window for credential theft.

The Broader Threat Landscape and Lessons

The LunexStealer campaign is one of many supply-chain attacks that blur the line between website security and user responsibility. The threat group UAC-0277 was attributed by Ukraine's CERT-UA based on malware signatures and behavioral analysis, though public attribution details remain limited. This reflects a common pattern: attackers compromise websites not to steal data from the site itself, but to use the site as a distribution vector for malware that targets visitors. It shifts the risk from the web application to the user's machine and credentials.

The lesson for individuals is that visiting a trusted website does not guarantee safety if that site has been compromised. For organizations, it emphasizes that security is not a single perimeter defense but a series of layers. Website administrators cannot assume their servers are secure; they must monitor for signs of unauthorized code, enforce strict code review practices and use automated tools to detect injected scripts.

What You Should Do Now

If you have visited any website in the past weeks and saw an unexpected Cloudflare verification check that asked for credentials, or if you received a file download after a verification page, treat this as a potential compromise. Change your passwords for any accounts you use regularly, starting with email and banking. Run a full antivirus or antimalware scan on your machine (tools like Malwarebytes or Windows Defender in offline mode can help). Monitor your bank and email accounts for unauthorized access attempts or unusual activity for the next 30 days. If you manage a website, audit your server logs for signs of unauthorized access or code changes, and consider hiring a security professional to perform a thorough forensic review if you suspect compromise.

Frequently Asked Questions

How do I know if a Cloudflare check is real or fake?

Real Cloudflare checks load from Cloudflare's own infrastructure and have a valid SSL certificate issued to Cloudflare Inc. or to the website you are visiting. You can inspect the certificate by clicking the lock icon in your browser address bar and viewing the certificate details. If the certificate is issued to someone else or looks suspicious, close the page immediately.

What data does LunexStealer actually steal?

LunexStealer typically harvests passwords, cookies, autofill data, browser history, cryptocurrency wallet credentials and session tokens. It may also exfiltrate local files or take screenshots of your screen. Once stolen, this data is sold or used for identity theft, account takeover or financial fraud.

Can I remove LunexStealer if I think I have been infected?

Yes, but you should not assume you can do it yourself completely. Run a professional antimalware tool in safe mode or use a Linux live USB boot to scan your system (the malware may prevent antivirus software from running from Windows). Change all passwords from a clean machine after removing the malware, because the stolen credentials are already in the attacker's hands. Consider professional help if you are unsure.

Why do attackers compromise websites instead of just sending phishing emails?

Website compromises bypass email filters, spam detection and user skepticism about email links. A visitor landing on a real website they trust is much more likely to comply with a security check than someone who receives a suspicious email. It also allows attackers to target many victims at once from a single compromise, making the attack more efficient.

Should I stop using Cloudflare-protected websites?

No. Cloudflare is a legitimate security service used by millions of sites. The problem is not Cloudflare itself but attackers impersonating it. Keep using these sites, but verify unexpected security checks before entering credentials and stay alert to unusual behavior.

Source: The Hacker News