Lunex Stealer spread via ClickFix on 100+ Ukrainian sites

Attackers have planted malicious code on more than 100 legitimate websites to push an information stealer onto the machines of Ukrainian users, according to CERT-UA, Ukraine's computer emergency response team.

The agency said it discovered the campaign in September. The malware delivered is Lunex Stealer, which can harvest passwords, authentication tokens and cryptocurrency wallet data, and also gives attackers remote access to infected computers.

A fake Cloudflare check

The infection starts on websites that look normal to visitors. The attackers inject code that shows a fake Cloudflare verification page. Instead of a checkbox or a puzzle, the page asks the visitor to prove they are human by copying a command and running it in PowerShell, the Windows command-line tool.

Running that command downloads and installs Lunex Stealer.

This trick is known as ClickFix. The victim performs the final step themselves, which helps attackers get around protections built to stop drive-by downloads. ClickFix has become an increasingly common way to get users to infect their own devices.

CERT-UA did not name the victims or say how many computers were infected. It did point to the kind of sites that were compromised. These included an online store and a website offering coloring pages for children. Neither is the sort of site most users would treat with suspicion.

The agency has not linked the operation to a known hacking group. It tracks the activity as UAC-0277.

A browser extension posing as Word

In some cases, Lunex goes further and installs a malicious extension for Chromium-based browsers called LunarAxe. The extension presents itself as "Microsoft Office Word Editor."

LunarAxe can steal cookies, browsing history and credentials that users enter into websites. It also gives attackers broad control over the browser. They can:

  • manipulate tabs
  • run JavaScript on webpages
  • take screenshots
  • change proxy settings

When paired with a second malicious component called NaiveMess, LunarAxe can reach past the browser and into the computer's file system. Attackers can then browse directories, read and overwrite files, and execute programs on the compromised machine.

Malware for hire

CERT-UA's findings build on research published earlier in September by Swiss cybersecurity company Ontinue, which documented similar Lunex activity aimed at Ukrainian-speaking users.

Ontinue describes Lunex as a relatively new malware-as-a-service platform. Its developers supply the malware and supporting infrastructure, and other criminals use it in their own attacks. According to the researchers, Lunex was built by a Russian-speaking developer or team and is sold to multiple independent cybercriminal operators.

The stealer targets seven Chromium-based browsers: Google Chrome, Microsoft Edge, Brave, Yandex Browser, Opera, Opera GX and Vivaldi. Along with cryptocurrency wallets, it goes after other sensitive information stored on the device.

Ontinue also found that the browser components provide persistent access to a victim's files. Attackers can browse directories, read and write files, download data and run programs. This access can survive even after the main Lunex executable has been removed from the computer.

The researchers identified 28 Lunex operator panels hosted in 13 countries. The control panel uses Russian as its default language and contains many Russian-language interface elements.

Ontinue said the platform still appears to be under active development. It is being used for credential theft and for phishing campaigns that impersonate legitimate brands.

Our Take

The most worrying detail is the persistence through browser components. If LunarAxe and NaiveMess can keep file system access after the main executable is gone, cleaning up an infection means more than deleting one file. Defenders should review installed browser extensions on affected machines, and an extension calling itself "Microsoft Office Word Editor" deserves a closer look.

The campaign also shows how far ClickFix has spread. Fake verification prompts that ask users to paste commands into PowerShell or a terminal now show up across many kinds of lures, much like the fake installer used in the CloudSyncD macOS backdoor campaign. A simple rule, that no real CAPTCHA asks you to run a command, could be one of the cheapest defenses available.

Because Lunex is sold as a service, it is worth watching whether the same toolkit turns up outside Ukraine. Ukraine has also been dealing with state-linked threats such as the Russian mobile malware CERT-UA warned about recently. For now, though, UAC-0277 has not been attributed to any group, and the evidence so far points to profit-driven crime rather than espionage.