Wire Observer.
Security

Ukrainian Cyber Campaign Hijacks Over 100 Sites with ClickFix-Delivered Lunex Spyware

Ukrainian Cyber Campaign Hijacks Over 100 Sites with ClickFix-Delivered Lunex Spyware

Ukraine's national computer emergency response team, CERT-UA, disclosed that more than a hundred websites have been infiltrated by a malicious operation that leverages counterfeit Cloudflare verification pages to deliver the Lunex infostealer. The scheme, dubbed the ClickFix campaign, redirects unsuspecting visitors into a familiar trap that installs the data‑stealing malware on their devices.

Investigators say the attackers replace legitimate Cloudflare verification prompts with forged versions that mimic the look and wording of the service's security checks. When users attempt to pass the bogus verification, they are silently rerouted to a download payload that drops Lunex onto the system. The malware then begins harvesting credentials, browser histories, and other sensitive information, transmitting it back to command‑and‑control servers.

The ClickFix moniker originated from earlier campaigns that used similar fake verification pages to spread ransomware and other threats. This iteration marks a shift toward espionage‑type software, highlighting the adaptable nature of the threat actors behind the operation. While the precise identity of the group remains unknown, the use of Cloudflare's brand suggests a focus on exploiting trust in widely adopted web security services.

Cybersecurity experts note that the scale of the compromise—over one hundred compromised domains—indicates a coordinated effort to target a broad audience, possibly aiming at both individual users and small businesses operating in the region. The choice of Ukraine as a primary theater aligns with a pattern of heightened cyber activity linked to the ongoing conflict and heightened geopolitical tensions.

In response, CERT-UA has issued advisories urging site administrators to audit their Cloudflare configurations, verify the integrity of verification pages, and apply security patches promptly. Users are cautioned to avoid interacting with unexpected verification prompts, especially those that request downloads or additional clicks, and to keep anti‑malware tools up to date.

The discovery underscores the persistent risk posed by social‑engineering tactics that blend legitimate security mechanisms with malicious intent. As authorities continue to track the campaign's infrastructure, analysts expect further warnings and possibly coordinated takedown efforts to disrupt the attackers' command network and mitigate the spread of Lunex.

Source: The Record
Kabir Rao — Security desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related