100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer

Dozens of websites have been compromised and are using fake Cloudflare checks to deliver a malicious payload known as LunexStealer, which can siphon off sensitive user data. The security threat has left many users wondering if their online activities are truly secure.

The compromised websites appear to be legitimate businesses and organizations that are unwittingly hosting the malware on their servers. Upon visiting these sites, unsuspecting users may be greeted with a fake Cloudflare check, which is meant to reassure them of their safety and authenticity. However, in reality, this “check” is nothing more than a ruse designed to evade detection and deliver the malicious payload.

LunexStealer works by taking advantage of website visitors’ trust in Cloudflare, a popular web application security platform that provides protection against common web vulnerabilities such as SQL injection and cross-site scripting (XSS). By mimicking Cloudflare’s checks, the malware is able to bypass many security measures in place on compromised websites. Once inside, LunexStealer can exfiltrate sensitive data from infected devices, including login credentials, credit card numbers, and personal identifiable information.

This security threat has significant implications for users who frequent these compromised websites. For one, it highlights the importance of verifying a website’s authenticity before sharing sensitive information or logging in with credentials. Even if a site appears to be secure, malicious actors can still exploit vulnerabilities on its server-side infrastructure. This incident also underscores the need for organizations and businesses to implement robust security measures, including regular software updates, vulnerability scanning, and employee education on cybersecurity best practices.

The compromised websites are likely using fake Cloudflare checks as a “dropper” to deliver LunexStealer. A dropper is a type of malware that downloads additional malicious payloads onto an infected device. In this case, the dropper is designed to evade detection by masquerading as legitimate traffic from Cloudflare. This tactic allows the attackers to bypass traditional security measures and inject their payload into the compromised site’s visitors.

The compromised websites affected by this security threat are scattered across various industries, including finance, e-commerce, and healthcare. Users who have visited these sites in recent weeks may be at risk of having their sensitive information compromised. While Cloudflare has taken steps to mitigate the issue, it is essential for users to remain vigilant when interacting with online services.

As a practical takeaway, readers should exercise caution when visiting websites that display fake security checks or alerts. Before sharing sensitive information or logging in with credentials, verify a site’s authenticity by checking its address bar for any signs of tampering and ensuring the connection is secure (https). Additionally, keep software up-to-date and install reputable antivirus solutions to minimize the risk of falling victim to such attacks.


Source: The Hacker News — 2026-10-07