Over 100 Compromised Websites Deploy LunexStealer via Fake Cloudflare Checks
CERT-UA attributes campaign to UAC-0277; malicious JavaScript injections target visitors to steal credentials and browser data

Key Takeaways
- Over 100 compromised websites were injecting malicious JavaScript to deliver LunexStealer.
- The attack uses fake Cloudflare checks to evade detection and trick visitors into executing the payload.
- The campaign is attributed to the threat cluster UAC-0277, as tracked by CERT-UA.
Related Security News

16 Malicious Firefox Extensions Disguised as Crypto Wallets Steal Recovery Phrases
Cybersecurity researchers have uncovered a cluster of 16 malicious Mozilla Firefox extensions that masquerade as legitimate cryptocurrency wallet interfaces and desktop utilities. The extensions intercept and steal recovery phrases and private keys during wallet import flows, attempting to exfiltrate the sensitive data to remote servers controlled by threat actors. The add-ons were distributed through addons.mozilla.org and similar channels, targeting cryptocurrency users globally.




