Security News

Fake Cloudflare Checks on Hacked Websites Spread Password-Stealing Malware in Ukraine

The Record · 6 Oct 2026
Key Takeaway Train your staff to never copy and run commands from a website to prove they are human, because no legitimate verification check will ask them to do so.

Ukraine's computer emergency response team, CERT-UA, has reported a campaign in which attackers compromised more than 100 legitimate websites to infect visitors with information-stealing malware. The activity was discovered in September. Visitors saw a fake Cloudflare verification page that told them to copy and run a command in PowerShell, a Windows command-line tool, to prove they were human. Following those instructions installed Lunex Stealer, which can steal passwords, authentication tokens and cryptocurrency wallet data, and give attackers remote access. The affected sites included an online store and a website offering coloring pages for children. CERT-UA did not identify the victims or say how many computers were infected.

In some cases, Lunex also installs a malicious Chromium browser extension called LunarAxe, disguised as "Microsoft Office Word Editor". It can steal cookies, browsing history and credentials entered into websites, and gives attackers wide control over the browser. Combined with a component called NaiveMess, it can also reach the computer's file system, letting attackers browse folders, read and overwrite files and run programs. The tactic of tricking people into running malicious commands themselves is known as ClickFix, and it is becoming increasingly common.

CERT-UA has not linked the operation to a known hacking group and tracks it as UAC-0277. Swiss firm Ontinue earlier documented similar Lunex activity and described it as a relatively new malware-as-a-service platform, sold by a Russian-speaking developer or team to multiple independent criminal operators.

ClickFix infostealer Lunex malware-as-a-service browser security

Summarised by CISO AI from The Record, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.