Skip to content

Security3 publishersIndependently confirmed2 min readPublished Updated

Fake Cloudflare checks on more than 100 hacked sites trick Ukrainians into installing Lunex Stealer

CERT-UA says attackers planted fake Cloudflare checks on more than 100 legitimate websites to get visitors to install Lunex Stealer themselves. Ontinue says its browser components can keep file access after the stealer is deleted, so cleanup has to reach the browsers.

The Watch · Security desk

How we use AISend a correction

What happened

  • CERT-UA found the campaign in September, tracks it as UAC-0277 and has not tied it to any known hacking group.
  • Lunex steals passwords, authentication tokens and cryptocurrency wallet data, and gives the attacker remote access to the infected computer.
  • In some infections Lunex adds LunarAxe, a Chromium extension posing as "Microsoft Office Word Editor" that steals cookies, browsing history and typed credentials.
  • Swiss firm Ontinue calls Lunex a malware-as-a-service platform from a Russian-speaking developer or team, sold to multiple independent criminal operators.
  • Ontinue found 28 Lunex operator panels hosted across 13 countries.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure The lure runs on hacked legitimate sites, so visitors get no warning from a site's reputation, and any compromised page can serve the fake check.
  • decision The chain needs the visitor to paste and run a PowerShell command, so on managed machines whether ordinary users can run PowerShell decides whether this lure gets through.
  • constraint With Lunex rented to several crews, taking down UAC-0277's sites or panels would leave the platform working for its other customers.

The 100-site count measures delivery points. CERT-UA did not identify the victims or say how many computers were infected [10]. The compromised sites it named are an online store and a site offering coloring pages for children [6]. The Record describes the targets as Ukrainian users [1].

On the victim's machine the attack needs one action from the user. The fake Cloudflare page tells the visitor to copy a command and run it in PowerShell, the Windows command-line tool, as proof of being human [2]. The Record calls this technique, ClickFix, an increasingly common way of getting users to infect their own devices [9].

The browser components make removal harder. LunarAxe lets the attacker manipulate tabs, run JavaScript on webpages, take screenshots and change proxy settings [5]. Paired with a second component, NaiveMess, it reaches the file system: the attacker can browse directories, read and overwrite files and execute programs [7]. According to Ontinue, that access can remain after the main Lunex executable is removed [13]. A responder who deletes the binary still has to check the extensions in every Chromium browser on the host, including the one LunarAxe installs [18]. Ontinue counts seven targeted browsers: Chrome, Edge, Brave, Yandex Browser, Opera, Opera GX and Vivaldi [12].

CERT-UA's report follows Ontinue's research, published earlier in September, on similar Lunex activity aimed at Ukrainian-speaking users [11]. Ontinue says the platform still appears to be under active development and is being used for credential theft and for phishing that impersonates legitimate brands [15]. If Ontinue is right that Lunex is sold to independent operators, the 100-site campaign is one crew's use of a kit that others also run [19]. The control panel uses Russian as its default language and carries many Russian-language interface elements, according to the researchers [17].

What to watch

  • CERT-UA publishing an infection count or naming affected organisations, to show how many of the 100-plus sites produced compromised machines.
  • Any link between UAC-0277 and one of the 28 Lunex operator panels Ontinue found, or an attribution to a known group.
  • Lunex ClickFix lures turning up on compromised sites aimed at users outside Ukraine, given panels hosted in 13 countries.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories