Over 100 hijacked websites got visitors to infect themselves.

Ukraine’s emergency response team says Lunex steals passwords, tokens and cryptocurrency wallet data.

Fake Cloudflare verification pages told visitors to run a PowerShell command, so users installed the malware themselves.

The team has not attributed the campaign to a known hacking group.

It has not said how many computers were infected or who the victims are.

How each outlet framed it
The Record
reconstructs social engineering chain: fake Cloudflare verification page coerces PowerShell command copying to deploy Lunex Stealer

Sources: The Record