WORLDTECH NEWS Global technology intelligence.Contact
โ† Back to WORLDTECH
Cybersecurity SINGLE SOURCE

ClickFix campaign in Ukraine compromises over 100 websites to spread Lunex malware

Two analysts silhouetted in front of monitors in a security operations centerAI illustration
WORLDTECH illustration ยท AI-generated (Canva)

What happened

CERT-UA found fake Cloudflare verification pages that led visitors into a now-familiar ClickFix trap. Ukraine's computer emergency response team, CERT-UA, said the campaign, discovered in September, involved attackers injecting malicious code into legitimate websites.

This time the goal was to infect machines with an infostealer. Visitors to those sites were shown a fake Cloudflare verification page that told them to copy and run a command in PowerShell, a Windows command-line tool, to prove they were human.

Instead, following the instructions downloaded and installed Lunex Stealer, malware that can steal passwords, authentication tokens, and cryptocurrency wallet data, as well as give attackers remote access to infected computers. The technique of asking unwitting victims to copy and run malicious commands, known as ClickFix , has become an increasingly common way of tricking users into infecting their own devices.

CERT-UA did not identify the victims of the campaign or say how many computers were infected. Among the compromised sites, however, were an online store and a website offering coloring pages for children.

Key facts

  • CERT-UA โ€” found: fake Cloudflare verification pages that led visitors into a now-familiar ClickFix trap

Sources & evidence