ClickFix campaign in Ukraine compromised 100+ sites to spread Lunex malware
CERT-UA said attackers compromised more than 100 Ukrainian websites in September, using a fake Cloudflare verification page to trick visitors into running a PowerShell command. The technique installed Lunex Stealer, which harvests passwords, tokens and crypto wallet data and gives attackers remote access.
- CERT-UA tracks the campaign under the identifier UAC-0277
- Compromised sites included an online store and a children's coloring pages site
- Lunex is a malware-as-a-service platform run by a Russian-speaking team
- The LunarAxe extension disguises itself as Microsoft Office Word Editor
Read next
Security