Over 100 Ukrainian Websites Compromised by Malware Scheme
Article Content
- •Over 100 Ukrainian websites compromised with malware disguised as CAPTCHA.
- •Users are tricked into executing commands that install harmful software.
- •The attacks specifically target Windows users from search engines.
The State Special Communications Service of Ukraine reported over 100 hacked websites that display a fake 'I am not a robot' verification page. This scheme, attributed to the group UAC-0277, tricks users into executing a command that installs malware on their Windows systems. The malicious JavaScript code embedded in these sites prompts users to run commands via Win+R, CMD, or PowerShell, leading to the installation of harmful software. The attacks target Windows users arriving from search engines like Google and DuckDuckGo, showing the fake verification page no more than twice every 12 hours. CERT-UA emphasizes that legitimate CAPTCHA or Cloudflare checks never require users to execute system commands. The malware can steal sensitive information and may allow remote control of infected devices. Users are advised to close any suspicious pages immediately.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track LunexStealer and Ethereum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
How can I identify the fake CAPTCHA?
What should I do if I encounter this fake verification?
Is this attack limited to certain websites?
Continue Reading
LunexStealer Malware Campaign Compromises 100+ Ukrainian Websites In September 2026, Ukraine's CERT-UA identified over 100 compromised websites used to distribute LunexStealer malware. The attackers injected malicious JavaScript into legitimate sites, prompting users to execute commands under the guise of a Cloudflare verification page. This ClickFix technique led to the…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…