ClickFix campaign hits 100+ Ukrainian sites with Lunex stealer
CERT-UA, tracking the activity as UAC-0277, says more than 100 compromised websites push fake Cloudflare checks that trick users into running PowerShell and installing Lunex Stealer.
Ukraine's computer emergency response team, CERT-UA, says more than 100 compromised websites are serving a ClickFix lure to Ukrainian users, ending in an infostealer it calls Lunex. CERT-UA is tracking the activity under the identifier UAC-0277 and has not attributed it to a known group. The campaign was discovered in September 2026 and reported publicly on 6 October, relayed by The Record.
How the lure works
The compromised sites display a fake Cloudflare "verify you are human" page. Instead of a checkbox, the page instructs the visitor to copy a command and run it in PowerShell to "complete verification" — the ClickFix pattern, which outsources execution to the victim and sidesteps the download prompts and mark-of-the-web checks that catch a dropped file. Running the command pulls down Lunex.
What Lunex does
Per CERT-UA, Lunex Stealer harvests passwords, authentication tokens and cryptocurrency wallet data, and gives the operator remote access to the infected host. It also deploys browser extensions — named LunarAxe and NaiveMess — to extend its reach inside the browser. Swiss security firm Ontinue published concurrent research identifying Lunex as a Russian-language malware-as-a-service platform, counting 28 operator panels hosted across 13 countries — a scale that puts this well beyond a single crew.
CERT-UA did not publish file hashes, domains or other machine-readable indicators in a usable form in this disclosure, so we are not reproducing an IOC block here. Operators running detections should pull the indicators directly from the CERT-UA advisory for UAC-0277 and from Ontinue's writeup rather than from secondary coverage.
What to do today
- Block clipboard-to-PowerShell execution paths. The ClickFix technique depends on a user pasting a command into a Run dialog or terminal. Where feasible, constrain PowerShell with Constrained Language Mode and log
Microsoft-Windows-PowerShell/Operationalevent 4104 (script-block logging) for review. - Hunt for the browser extensions. Search managed browsers for LunarAxe and NaiveMess and for unexpected unpacked/developer-mode extensions.
- Treat token theft as the real damage. Lunex grabs session tokens, so password resets alone are insufficient — invalidate active sessions and re-issue tokens for any host that ran an unexpected PowerShell command.
- Warn users about "verification" pages that ask you to run a command. A real CAPTCHA never tells you to open PowerShell.
Context
ClickFix has become the default delivery technique of 2026 precisely because it moves the risky step onto the user and past most file-based defenses — the same pattern we have covered against Windows Run-dialog abuse and browser-cache smuggling. What is notable here is the combination: a MaaS stealer with dozens of operator panels, bolted onto a mass website-compromise campaign aimed at a single country's users. Attribution stays open — CERT-UA's UAC-0277 is a tracking label, not a named actor — and we are leaving it there rather than guessing.