
ClickFix infections via 100+ Ukrainian sites deliver Lunex with LunarAxe browser persistence
Over 100 Ukrainian websites were injected with ClickFix JavaScript to deliver the Russian-developed Lunex Stealer and its LunarAxe extension. CERT-UA and Ontinue reporting show persistent browser and file-system access with no public victim or infection metrics. The activity highlights MaaS distribution risks in a conflict zone where web compromise directly affects operational security.
Defenders should prioritize PowerShell logging, browser extension audits, and rapid takedown coordination with Ukrainian registrars. Absent public attribution or sinkholing data, the infrastructure remains available for reuse in follow-on operations against the same user base.
CERT-UA: At least 30 additional Ukrainian domains will show UAC-0277 ClickFix injection within 45 days.
Sources (3)
- [1]Primary Source(https://therecord.media/clickfix-campaign-ukraine-lunex-stealer)
- [2]Supporting Source(https://www.ontinue.com/research/lunex-stealer-ukraine)
- [3]Supporting Source(https://cert.gov.ua/article/62741)