Fake “I’m not a robot” verification — hackers are infecting Ukrainians’ PCs with a dangerous virus
Kyiv • UNN
Hackers have replaced Cloudflare CAPTCHA on more than 100 websites and are tricking Windows users into running dangerous PowerShell commands. The virus steals passwords and provides remote access to PCs.

Hackers are massively targeting Ukrainians, disguising malware as an “I’m not a robot” check. Attackers replace Cloudflare CAPTCHA on compromised websites and force users to execute dangerous commands, after which the LUNEXSTEALER virus is installed on the computer. The State Service of Special Communications and Information Protection reports this, UNN writes.
Details
CERT-UA reports a new large-scale infection campaign: in September, attackers hacked more than 100 websites and replaced the Cloudflare check on them with a fake page. Windows users who visited such pages from Google or other search engines were instructed to copy text and execute a command in PowerShell. Following the instructions led to the LUNEXSTEALER virus being installed on the computer.
It is noted that the malware disguises itself as legitimate files, exploits vulnerable drivers, and covertly embeds a fake “Microsoft Office Word Editor” extension in the browser. The consequences include the theft of passwords and browsing history, and even full remote control over the PC.
The State Service of Special Communications and Information Protection warned that no genuine CAPTCHA or Cloudflare will ask users to open Win+R or PowerShell or paste commands.