Cyberattack Spreads Malware Through Fake Verification Checks on 100+ Websites
In September 2024, over 100 websites were hacked as part of a cyberattack campaign orchestrated by the UAC-0277 group. The hackers employed a technique called ClickFix, which distributed malicious software through fake 'I'm not a robot' verification prompts. These counterfeit checks deceived users into executing harmful commands on their devices, leading to the installation of the LUNEXSTEALER utility and a malicious browser extension disguised as an office document editor.
The attackers used blockchain platforms Polygon and Ethereum to manage their operations, complicating efforts to track their activities. The malware spread through fraudulent Cloudflare protection pages, targeting Windows users with fake pop-ups that appeared no more than twice daily per user. This approach reduced visibility but effectively tricked users into running harmful system commands.
With control over victims' devices, the hackers could steal passwords and session data. In response, CERT-UA issued guidance for system administrators to mitigate the threat. Recommendations included disabling the Win+R shortcut for standard user accounts, restricting execution of unverified software packages, and enforcing whitelists for browser extensions. CERT-UA also urged immediate reporting of any hacked websites to facilitate protective actions.
This incident highlights the growing complexity of cyber threats, with attackers continually developing sophisticated methods to deceive users. The recent attack on Ukrainian websites using the Psychedelic Stealer further underscores the urgent need for enhanced cybersecurity measures to protect sensitive data and user privacy.