Therecord.Media Lunex Malware Campaign Infects Over 100 Ukrainian Websites
Article Content
- •Over 100 websites compromised to spread Lunex malware targeting Ukrainian users.
- •Attackers use social engineering tactics, prompting users to run commands in PowerShell.
- •Lunex Stealer can steal sensitive information and install malicious browser extensions.
A new cyber campaign in Ukraine has compromised over 100 legitimate websites to spread Lunex malware, according to CERT-UA. Discovered in September 2026, attackers injected malicious JavaScript code into these sites, prompting users to execute commands in PowerShell under the guise of a Cloudflare verification page. This led to the installation of Lunex Stealer, which can steal sensitive information like passwords and cryptocurrency data. The malware also installs a browser extension, LunarAxe, disguised as 'Microsoft Office Word Editor,' allowing extensive control over the victim's browser. CERT-UA has not attributed this operation to a known hacking group but is tracking it under the identifier UAC-0277. The campaign highlights the increasing use of social engineering techniques to exploit users directly. Users are advised to avoid executing any commands prompted by suspicious pages.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track ClickFix in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What should users do if they encounter the fake verification page?
Is the Lunex malware actively being exploited?
What measures can be taken to protect against this malware?
Continue Reading
New ChainScript RAT Exploits ClickFix Lures with Blockchain C2 A newly discovered Node.js remote access trojan (RAT) named ChainScript is being deployed through ClickFix social engineering tactics, targeting Windows systems. The malware utilizes a unique command-and-control (C2) discovery method by querying a Polygon blockchain smart contract to dynamically rotate its server…
Cybercriminals Exploit ChatGPT Custom GPTs for ClickFix RAT Attacks A new ClickFix campaign has been discovered that exploits ChatGPT Custom GPTs to impersonate legitimate products, luring users into executing malicious code. Cybersecurity firm Huntress reported that at least 40 users have been infected, with two confirmed incidents linked to Custom GPT instances. The attackers…