chiprook
← Security
SecurityOctober 6, 2026, 20:17

ClickFix campaign in Ukraine compromised 100+ sites to spread Lunex malware

CERT-UA said attackers compromised more than 100 Ukrainian websites in September, using a fake Cloudflare verification page to trick visitors into running a PowerShell command. The technique installed Lunex Stealer, which harvests passwords, tokens and crypto wallet data and gives attackers remote access.

ClickFix campaign in Ukraine compromised 100+ sites to spread Lunex malware
#CERT-UA#Lunex#ClickFix#PowerShell
Read next
Security

Sekoia uncovers Exvicy, a new ClickFix MaaS built on ErrTraffic code

Security

Hackers host fake ChatGPT model on official site to spread ClickFix malware

Security

Hacked Ukrainian Sites Spread Psychedelic Stealer via Fake Cloudflare ClickFix

Security

Warlock ransomware spread via SYSVOL after SharePoint compromise