Ukraine's computer emergency response team, CERT-UA, has disclosed a campaign in which attackers compromised more than 100 legitimate websites and injected malicious code into them. Visitors to the affected sites, which included an online store and a children's coloring-page site, were shown a fake Cloudflare verification page instructing them to copy and run a PowerShell command to prove they were human. Following the instructions instead installed Lunex Stealer, a piece of malware designed to harvest passwords, authentication tokens, and cryptocurrency wallet data, and to give attackers remote access to infected machines. CERT-UA has not attributed the operation to a known group and is tracking it as UAC-0277.
Some infections also dropped a malicious extension for Chromium-based browsers called LunarAxe, which disguises itself as "Microsoft Office Word Editor." The extension can steal cookies, browsing history, and credentials, and gives attackers broad control over the browser, including the ability to run JavaScript, take screenshots, and change proxy settings. When paired with another component called NaiveMess, LunarAxe can reach beyond the browser to the file system, letting attackers browse directories, read and overwrite files, and execute programs.
Separate research published earlier in September by Swiss firm Ontinue describes Lunex as a relatively new malware-as-a-service platform developed by a Russian-speaking developer or team and sold to multiple cybercriminal operators. Ontinue found that Lunex targets seven Chromium-based browsers, including Chrome, Edge, Brave, Yandex, Opera, Opera GX, and Vivaldi, and that its browser components can provide persistent file access even if the main executable is removed. The researchers identified 28 operator panels hosted across 13 countries, with a control panel that uses Russian as its default language. The two reports align on the core threat, with Ontinue's findings adding detail on the malware's distribution model and persistence mechanisms.