16864 visitors online

Hackers have breached more than 100 websites in Ukraine to steal passwords and user data, - State Special Communications Service

CERT-UA has identified over 100 compromised websites in Ukraine – hackers are stealing usernames and passwords

In September, CERT-UA experts identified over 100 compromised websites through which hackers were distributing malware. Once a system is infected, the attackers can steal usernames, passwords, and browsing history, as well as remotely control the victim’s computer.

This was reported by the State Service for Special Communications and Information Protection of Ukraine, according to Censor.NET.

It is reported that hackers are behind the campaign, and their activity is being tracked under the identifier UAC-0277. They use the ClickFix technique to infect devices.

Cybercriminals compromise legitimate websites and inject malicious JavaScript code into them. Consequently, a dangerous page may appear even when visiting a site the user is familiar with.

On the compromised website, visitors are shown a fake Cloudflare verification page. Under the guise of a standard ‘I’m not a robot’ verification, the user is asked to copy and execute a specific command.

If a user follows these instructions, malware is downloaded and installed onto their computer.

Following infection, a malicious extension, disguised as Microsoft Office Word Editor, is silently installed in the browser. It enables the theft of usernames, passwords, and browsing history, and also allows cybercriminals to remotely control the computer.

CERT-UA has urged users to close the page immediately if, during a purported security check, they are asked to copy and execute a command. This rule also applies to familiar or well-known websites.