- CERT-UA says attackers hacked more than 100 websites to show a fake Cloudflare check that installed Lunex Stealer on Ukrainian visitors' computers.
- Ordinary sites, including a store and a children's coloring site, became the delivery route, so a company's own domain can carry an attacker's message.
- Check your sites for injected code, review browser extensions on staff machines, and make sure removing malware also removes browser-level access.
The most useful detail in this story is a small one. Among the sites hacked to spread malware in Ukraine was a website offering coloring pages for children. The site's owner appears not to have been the target. The trust of its visitors looks to have been the tool.
Ukraine's computer emergency response team, CERT-UA, discovered the campaign in September, according to The Record. Attackers injected malicious code into more than 100 legitimate websites. The Record reports that an online store was also among them.
How the trick works
Visitors to the affected sites saw a fake Cloudflare check page. It asked them to paste and run a command in PowerShell. That is a Windows tool for typing commands. The page claimed this would show the visitor was a real person.
This technique is known as ClickFix. The Record describes it as an increasingly common way of getting people to infect their own devices. The attacker does not need to break into the computer. The visitor performs the key step.
Following the instructions installed Lunex Stealer. CERT-UA says it can take passwords, authentication tokens and cryptocurrency wallet data. It also gives attackers remote access.
Cleanup may leave access behind
In some cases Lunex also installs a browser extension called LunarAxe. CERT-UA says it poses as "Microsoft Office Word Editor." It targets Chromium-based browsers.
Once installed, LunarAxe can collect the user's cookies and browsing history. It can also capture logins typed into websites.
It gives attackers wide control of the browser. They can open and close tabs, run JavaScript on pages, take screenshots and change proxy settings. Paired with a component called NaiveMess, LunarAxe can reach the file system. Attackers can browse folders, read and overwrite files, and launch programs.
Ontinue, a Swiss cybersecurity company, published research earlier in September on similar Lunex activity. It aimed at Ukrainian-speaking users. Ontinue found that the browser components can keep access to a victim's files. That access can remain even after the main Lunex program is removed.
This matters for incident response. Deleting the malicious program may not end the problem. A team that stops there could believe the job is done when it is not.
A rented platform, not a single gang
Ontinue places Lunex in the rental-malware category. The platform is fairly young. Its developers lend their tools and servers to other criminals, who run their own attacks. Ontinue says the developer or team is Russian-speaking.
The researchers found 28 operator control panels hosted across 13 countries. They say the platform still appears to be under active development. They also say it is used for credential theft and for phishing that impersonates legitimate brands.
CERT-UA has not tied the campaign to a known hacking group. It tracks the activity as UAC-0277.
What the reports do not say
CERT-UA did not name the victims. It did not say how many computers were infected. The Record's account does not explain how the websites were broken into. These gaps limit what any organization can conclude about its own exposure.
The campaign described is aimed at Ukrainian users. The reporting does not tie the technique or the rented platform to one country. It also gives no figures for other regions.
The lesson: your domain is borrowed authority
This is a reminder of who carries the risk. A small site owner with no interest in geopolitics can become the delivery route for someone else's attack. Visitors trust the site, so they trust the page that appears on it.
A fake security check works for a plain reason. People have learned to click through verification screens. The attacker only has to borrow a familiar one.
Questions to put to your team
Do we know when code on our public sites changes, including scripts we did not write? Who is alerted, and how fast? A hacked site that hosts a fake check page is a brand problem as well as a security one.
Do staff know that no real human check asks them to paste a command into PowerShell? Can ordinary users run PowerShell at all, and does their job need it?
Do we keep an inventory of browser extensions on company machines? An extension posing as an office tool is easy to miss.
When we clean an infected machine, do we also check browser extensions and stored sessions? Do we reset passwords and tokens? Ontinue's finding says removing the main program may not be enough.
A website can be honest and still be used against its own visitors. Plan for both sides of that.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: The Record.





