Hackers exploit fake verification checks to infect over 100 websites
In September 2024, over 100 websites fell victim to a cyberattack orchestrated by the UAC-0277 group. The hackers exploited fake 'I'm not a robot' verification prompts to distribute malicious software, as reported by CERT-UA. This technique, known as ClickFix, tricks users into running harmful commands on their devices. The attackers use blockchain platforms Polygon and Ethereum to manage their operations, making it difficult to trace their activities.
The malware spreads through counterfeit Cloudflare protection pages that target Windows users. These fraudulent pop-ups appear no more than twice daily per user, limiting their visibility. Once infected, victims have the LUNEXSTEALER utility and a malicious browser extension installed, disguised as an office document editor. These tools allow attackers to steal passwords and session data.
CERT-UA has issued guidance to mitigate the threat. They advise disabling the Win+R shortcut for standard user accounts, restricting unverified software execution, and enforcing whitelists for browser extensions. Immediate reporting of any hacked websites is also urged to protect users' information security.
The incident highlights the growing complexity of cyber threats. Attackers are developing sophisticated methods to deceive users, emphasizing the need for enhanced cybersecurity measures. Continuous vigilance and user education are essential to combat these evolving risks.