Hackers compromised 100 Ukraine websites to deliver malware
Over 100 websites in Ukraine were hacked to deliver the Lunex Stealer malware, according to CERT-UA. Attackers inserted harmful code so visitors would be presented with a fraudulent verification page. Windows users who followed instructions on that page unwittingly installed malware capable of stealing passwords, browser data, and cryptocurrency wallets. The malware can also enable attackers to control browser settings and access files on victims’ computers.
- Over 100 legitimate sites compromised in Ukraine
- Victims tricked into running PowerShell commands
- Lunex Stealer extracts passwords and wallet data
- Malware can control browsers and access local files
- CERT-UA tracking activity as cluster UAC-0277
Sources covering this
In this story
More in Cybersecurity
Four states sue TP-Link over router security claims
Florida and three other US states have filed lawsuits against TP-Link, alleging the company misled consumers about its routers' security…
Outlook will block MSIX file attachments in November
Microsoft will begin blocking .msix and .msixbundle attachments in Outlook on the web and the new Outlook for Windows starting in November.
Major software vendors patch critical vulnerabilities
Cisco Talos researchers reported multiple vulnerabilities in products from Microsoft, Adobe, Apple, and Foxit.
PoeLLM malware builds botnet targeting AI services
Researchers have identified malware named PoeLLM that has compromised over 3,400 servers since April by targeting open-source AI services.