Skip to content
Lunex Malware Campaign Infects Over 100 Ukrainian Websites

Lunex Malware Campaign Infects Over 100 Ukrainian Websites

First seen 6 Oct 2026, 17:04 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 18:04 UTC
  • •Over 100 websites compromised to spread Lunex malware targeting Ukrainian users.
  • •Attackers use social engineering tactics, prompting users to run commands in PowerShell.
  • •Lunex Stealer can steal sensitive information and install malicious browser extensions.

A new cyber campaign in Ukraine has compromised over 100 legitimate websites to spread Lunex malware, according to CERT-UA. Discovered in September 2026, attackers injected malicious JavaScript code into these sites, prompting users to execute commands in PowerShell under the guise of a Cloudflare verification page. This led to the installation of Lunex Stealer, which can steal sensitive information like passwords and cryptocurrency data. The malware also installs a browser extension, LunarAxe, disguised as 'Microsoft Office Word Editor,' allowing extensive control over the victim's browser. CERT-UA has not attributed this operation to a known hacking group but is tracking it under the identifier UAC-0277. The campaign highlights the increasing use of social engineering techniques to exploit users directly. Users are advised to avoid executing any commands prompted by suspicious pages.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-01
Campaign discovered
CERT-UA identified a new malware campaign involving over 100 compromised websites in Ukraine.
Therecord.Media
2026-10-06
Public advisory issued
CERT-UA warns users about the malware campaign and advises against executing unknown commands.
Ua.News

More articles in this cluster (3)

Following this threat?

Track ClickFix in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What should users do if they encounter the fake verification page?
Users should close the page immediately and avoid executing any commands prompted.
Is the Lunex malware actively being exploited?
Yes, the malware is actively being used in a campaign targeting Ukrainian users.
What measures can be taken to protect against this malware?
Users should be cautious of suspicious prompts and consider disabling the ability to run commands without administrator privileges.