CyberSecurity News
100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer
AI summary
Ukraine's Computer Emergency Response Team has discovered over 100 compromised websites that are using malicious JavaScript to deliver LunexStealer malware. The malware is also known as Psychedelic Stealer and is used for stealing information. The compromised websites are using fake Cloudflare checks to serve the malware. The activity was first observed in September 2026 and has been attributed to a threat cluster called UAC-0277. The threat cluster is responsible for injecting the malicious JavaScript into the compromised websites. The identity of those behind the threat cluster has not been disclosed.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

