ClickFix campaign in Ukraine compromises over 100 websites to spread Lunex malware
A ClickFix campaign compromised over 100 Ukrainian websites to deliver the Lunex information stealer.
CERT-UA said attackers compromised more than 100 Ukrainian websites and showed visitors a fake Cloudflare check that told them to run a PowerShell command. Following the ClickFix instructions installed Lunex Stealer, which steals passwords, authentication tokens, and cryptocurrency wallets and can give remote access. Some infections add the LunarAxe Chromium extension, disguised as a Microsoft Word editor, and NaiveMess for file-system access. Ontinue describes Lunex as Russian-language malware-as-a-service; CERT-UA tracks the activity as UAC-0277 and has not named a group.
71