ClickFix campaign in Ukraine compromises over 100 websites to spread Lunex malware
Hackers compromised more than 100 websites to infect Ukrainian users with information-stealing malw 2026-10-6 13:33:8 Author: therecord.media(查看原文) 阅读量:4 收藏

Hackers compromised more than 100 websites to infect Ukrainian users with information-stealing malware, according to a new report.

Ukraine's computer emergency response team, CERT-UA, said the campaign, discovered in September, involved attackers injecting malicious code into legitimate websites. Visitors to those sites were shown a fake Cloudflare verification page that told them to copy and run a command in PowerShell, a Windows command-line tool, to prove they were human.

Instead, following the instructions downloaded and installed Lunex Stealer, malware that can steal passwords, authentication tokens, and cryptocurrency wallet data, as well as give attackers remote access to infected computers.

The technique of asking unwitting victims to copy and run malicious commands, known as ClickFix, has become an increasingly common way of tricking users into infecting their own devices.

CERT-UA did not identify the victims of the campaign or say how many computers were infected. Among the compromised sites, however, were an online store and a website offering coloring pages for children.

In some cases, Lunex installs a malicious extension for Chromium-based browsers called LunarAxe, which disguises itself as “Microsoft Office Word Editor.” The extension can steal cookies, browsing history and credentials entered into websites. It also gives attackers extensive control over a victim’s browser, allowing them to manipulate tabs, run JavaScript on webpages, take screenshots and change proxy settings.

Combined with another malicious component called NaiveMess, LunarAxe can reach beyond the browser and access the computer’s file system. Attackers can browse directories, read and overwrite files and execute programs on the infected machine.

CERT-UA has not attributed the operation to a known hacking group and is tracking the activity under the identifier UAC-0277.

The findings add to research published earlier in September by Swiss cybersecurity company Ontinue, which documented similar Lunex activity targeting Ukrainian-speaking users.

Ontinue described Lunex as a relatively new malware-as-a-service platform, meaning its developers provide the malware infrastructure to other criminals who can use it in their own attacks.

The researchers said Lunex was developed by a Russian-speaking developer or team and is sold to multiple independent cybercriminal operators. 

Ontinue found that Lunex targets seven Chromium-based browsers, including Google Chrome, Microsoft Edge, Brave, Yandex Browser, Opera, Opera GX and Vivaldi, and can steal cryptocurrency wallets and other sensitive information.

The malware’s browser components can also provide persistent access to a victim’s files, allowing attackers to browse directories, read and write files, download data and execute programs. According to Ontinue, that access can remain even if the main Lunex executable is removed from the computer.

Researchers found 28 Lunex operator panels hosted across 13 countries. The platform’s control panel uses Russian as its default language and contains numerous Russian-language interface elements.

The researchers said the platform, which still appears to be under active development, is being used for credential theft and phishing campaigns impersonating legitimate brands.

Recorded Future

No previous article

No new articles

Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.


文章来源: https://therecord.media/clickfix-campaign-ukraine-lunex-stealer
如有侵权请联系:admin#unsafe.sh