Published

CERT-UA warns of large-scale malware campaign using fake Cloudflare pages on hacked sites

Ukraine's computer emergency response team CERT-UA has identified a large-scale malware distribution campaign attributed to the hacker cluster UAC-0277. In September 2026, attackers compromised more than 100 legitimate websites and injected malicious JavaScript that displays fake Cloudflare "I am not a robot" pages to Windows visitors arriving from search engines, tricking them into running commands that install credential-stealing malware.

Key points

  • CERT-UA (operating under the State Service of Special Communications, Держспецзв'язку) detected the campaign and attributes it to cluster UAC-0277.
  • In September 2026, more than 100 compromised legitimate websites were found to contain injected malicious JavaScript code.
  • The ClickFix technique displays a fake Cloudflare verification page to Windows users arriving from search engines such as Google, DuckDuckGo, meta.ua, and bigmir.net.
  • Users are prompted to copy and execute a command via the Win+R shortcut, Command Prompt, or PowerShell under the pretext of an "I am not a robot" check.
  • Executing the command installs the LUNEXSTEALER stealer and a malicious browser extension disguised as "Microsoft Office Word Editor" that steals logins, passwords, and browsing history and allows remote control of the device.
  • Attackers use the Polygon and Ethereum blockchain networks to manage infrastructure and rapidly change settings.
  • CERT-UA advises users to close any page requesting such actions, and to contact [email protected] to report compromised sites or incidents; admins are advised to block Win+R for ordinary accounts, restrict unsigned MSI installs, and use browser extension allowlists.

Why it matters

The campaign exploits more than 100 trusted, legitimate websites as infection vectors, dramatically expanding the pool of potential victims. Its success depends on social engineering rather than software exploits: a fake CAPTCHA/Cloudflare page convinces users to run malicious commands themselves, making it effective even against non-technical visitors. A successful infection hands attackers stolen credentials, browsing history, and full remote control of the victim's computer. The use of blockchain-based infrastructure (Polygon and Ethereum) lets attackers rotate settings quickly, complicating takedown efforts. The threat is currently live against Windows users arriving from major search engines, including Ukrainian-language portals, and CERT-UA has published concrete defensive guidance and a reporting channel.

What happened

Ukraine's national computer emergency response team CERT-UA, which operates under the State Service of Special Communications and Information Protection (Держспецзв'язку), announced the discovery of a large-scale malware distribution campaign that it attributes to the hacker cluster UAC-0277. During September 2026, CERT-UA recorded more than 100 compromised legitimate websites into which attackers had injected malicious JavaScript code.

The campaign uses the ClickFix technique. When a Windows user arrives at a compromised site from a search engine such as Google, DuckDuckGo, meta.ua, or bigmir.net, the site displays a fake Cloudflare "I am not a robot" verification page. The user is asked to copy and execute a command — via the Win+R keyboard shortcut, the Windows command line, or PowerShell. The fake prompt is shown to a given visitor no more than twice per 12 hours.

If the user runs the command, the LUNEXSTEALER stealer is downloaded and installed, and a malicious browser extension disguised as "Microsoft Office Word Editor" is silently added. The malware is masked as legitimate files and exploits vulnerabilities in Windows system drivers to bypass defenses. The installed extension steals logins, passwords, and browsing history, and gives attackers remote control of the infected computer. To manage their infrastructure and evade takedown, the attackers use the Polygon and Ethereum blockchain networks.

CERT-UA stresses that no legitimate CAPTCHA or Cloudflare check ever asks users to press Win+R, open a command line, or paste and run commands, and recommends immediately closing any page that does. System administrators are advised to block the Win+R dialog for ordinary user accounts, restrict installation of unsigned MSI packages without administrator rights, and use browser extension allowlists. Owners of compromised sites and users who encounter the attack are urged to contact CERT-UA at [email protected] for instructions and cleanup assistance.

Background

CERT-UA is Ukraine's national computer emergency response team, operating under the State Service of Special Communications and Information Protection (Держспецзв'язку). The ClickFix technique tricks users into executing malicious commands themselves by imitating legitimate security checks such as CAPTCHAs or Cloudflare verifications. Legitimate CAPTCHAs and Cloudflare checks never ask users to press Win+R, open the command line or PowerShell, or paste and run commands.