ClickFix campaign hijacks 100+ Ukrainian websites to spread Lunex stealer
CERT-UA says a ClickFix campaign tracked as UAC-0277 compromised more than 100 Ukrainian websites to push Lunex, a stealer sold as malware-as-a-service.
At a glance
- CERT-UA tracks the campaign, discovered in September, as UAC-0277 and has not tied it to a known group, The Record reported.
- Compromised sites showed fake Cloudflare checks telling visitors to copy and run a PowerShell command.
- Lunex steals passwords, tokens and crypto wallet data, gives remote access and installs a rogue browser extension called LunarAxe.
- Ontinue found 28 Lunex operator panels in 13 countries and says a Russian-speaking developer sells it to multiple criminal operators.
Ukraine's computer emergency response team, CERT-UA, has warned of a ClickFix campaign that compromised more than 100 legitimate Ukrainian websites to infect visitors with an information stealer called Lunex, The Record reported on October 6. The agency tracks the activity, discovered in September, as UAC-0277 and has not attributed it to any known threat group.
What happened
According to The Record, visitors to the compromised sites were shown a fake Cloudflare verification page that instructed them to copy and run a command in PowerShell to prove they were human. Following those instructions installed Lunex instead. Among the hijacked websites were online stores and a site offering children's coloring pages, the report said, and the campaign targeted Ukrainian-speaking users.
ClickFix has become one of the most widely used initial access techniques because it relies on the victim to execute the malicious command, bypassing many download-based protections.
Technical details
The Record reported that Lunex steals passwords, authentication tokens and cryptocurrency wallet data and gives attackers remote access to infected computers. It also installs a browser extension called LunarAxe, which poses as a "Microsoft Office Word Editor" add-on and targets seven Chromium-based browsers: Chrome, Edge, Brave, Yandex, Opera, Opera GX and Vivaldi. The extension collects cookies, browsing history and credentials.
A separate component named NaiveMess extends the operators' reach beyond the browser, allowing access to the file system and execution of programs. According to the report, this access can persist even after the main executable has been removed, which means deleting the original file is not enough to clean an infected machine.
Who is behind it
Swiss security company Ontinue, which also analyzed Lunex, identified 28 operator panels across 13 countries and described the malware as a malware-as-a-service platform. Ontinue said Lunex was developed by a Russian-speaking developer or team and is sold to multiple independent cybercriminal operators, noting that the control panel's default language is Russian. The company said the platform is used for credential theft and phishing that impersonates brands.
What to do
Users should treat any website asking them to paste and run commands in PowerShell, the Run dialog or a terminal as an attack; legitimate CAPTCHA and verification pages never require this. Organizations can reduce exposure by restricting PowerShell and the Run dialog for standard users, monitoring for PowerShell launched from browser-related activity, and auditing installed browser extensions for unknown add-ons such as one posing as a Word editor. Hosts suspected of infection should be fully remediated and all stored credentials and session tokens rotated.
Sources
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



