KyivOver 100 hijacked websites got visitors to infect themselves.
Ukraine’s emergency response team says Lunex steals passwords, tokens and cryptocurrency wallet data.
Fake Cloudflare verification pages told visitors to run a PowerShell command, so users installed the malware themselves.
The team has not attributed the campaign to a known hacking group.
It has not said how many computers were infected or who the victims are.
How each outlet framed it
- The Record
- reconstructs social engineering chain: fake Cloudflare verification page coerces PowerShell command copying to deploy Lunex Stealer
Sources: The Record