
Ukraine’s computer emergency response team, CERT-UA, reports that attackers compromised more than 100 legitimate websites in a campaign first seen in September and used them to infect visitors with an information stealer called Lunex. According to The Record, the victims included an online store and a site offering coloring pages for children. CERT-UA tracks the activity as UAC-0277 and has not tied it to a known hacking group; it did not say how many computers were infected.
Visitors to the injected sites saw a fake Cloudflare “verify you are human” page that told them to copy a command and run it in PowerShell. That is the ClickFix technique: the victim runs the malicious command themselves, so the download never looks like an exploit. The command installs Lunex Stealer, which takes passwords, authentication tokens and cryptocurrency wallet data and gives attackers remote access. In some cases it also installs a malicious Chromium browser extension called LunarAxe, disguised as “Microsoft Office Word Editor,” which can steal cookies, history and typed credentials and control tabs. Paired with a component called NaiveMess, it can also read and overwrite files and run programs on the machine.
Swiss security firm Ontinue separately described Lunex as a relatively new malware-as-a-service platform, sold by a Russian-speaking developer or team to independent criminal operators. It found Lunex targets seven Chromium-based browsers (Chrome, Edge, Brave, Yandex Browser, Opera, Opera GX and Vivaldi) and counted 28 operator panels hosted across 13 countries. Ontinue says the browser components can keep file access even after the main Lunex executable is removed.
How to check if you’re affected
Affected devices are Windows computers where someone pasted and ran a command from a web page’s “verification” prompt, particularly on Ukrainian sites visited since September. A real Cloudflare check never asks you to open PowerShell or the Run dialog. If you did run one:
- Disconnect the device, then change passwords for accounts saved or typed in the browser from a different, clean device.
- Sign out all sessions and re-enroll MFA on email, banking and crypto accounts, and move any cryptocurrency wallet funds to a new wallet.
- Open your Chromium-based browser’s extensions page (Chrome, Edge, Brave, Opera, Vivaldi or Yandex Browser) and remove “Microsoft Office Word Editor” if you did not install it.
- Scan with an up-to-date endpoint security product and consider reinstalling the OS, since the extension components can persist.
