#CERT-UA
Капча просить натиснути Win+R і вставити команду? Це пастка.

CERT-UA виявила 100+ зламаних сайтів із фальшивою перевіркою Cloudflare, яка встановлює інфостілер LunexStealer.

Як розпізнати атаку:
cybercalm.org/lunexstealer...
October 8, 2026 at 6:11 AM
For those who who found interest in our presentations at @labscon.bsky.social and @cyberwarcon.bsky.social this year detailing Russia's espionage against frontline targets, CERT-UA has released details around one of the groups we spoke about (UNC4221) here:

cert.gov.ua/article/6281...
CERT-UA
Урядова команда реагування на комп’ютерні надзвичайні події України, яка функціонує в складі Державної служби спеціального зв’язку та захисту інформації України.
cert.gov.ua
December 9, 2024 at 5:17 PM
Ukraine says Russian hackers are targeting country’s defense contractors
Ukraine says Russian hackers are targeting country’s defense contractors
Ukraine’s Computer Emergency Response Team (CERT-UA) said in a report published over the weekend that a hacking group has been targeting the country’s defense and military companies with phishing attacks.  The CERT identified the hacking group as UAC-0185…
tcrn.ch
December 9, 2024 at 5:39 PM
100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer
100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer
CERT-UA found 100+ compromised sites using ClickFix lures to distribute LunexStealer to Windows search visitors.
thehackernews.com
October 7, 2026 at 8:01 AM
We are honored to be hosting the Computer Emergency Response Team of Ukraine (CERT-UA) to get an updated picture on the threat landscape in Ukraine in their talk “FIFTY SHADES OF CYBER DURING THE WAR TIME”

Read more of CERT-UA's work on their website: cert.gov.ua
CERT-UA
Урядова команда реагування на комп’ютерні надзвичайні події України, яка функціонує в складі Державної служби спеціального зв’язку та захисту інформації України.
cert.gov.ua
October 10, 2025 at 3:20 AM
Ukraine warns Russian hackers are revisiting past breaches to prepare new attacks

therecord.media/ukraine-warn...
Ukraine warns Russian hackers are revisiting past breaches to prepare new attacks
In a new report, CERT-UA said attackers are revisiting previously breached infrastructure to check whether access is still available, whether exploited vulnerabilities have been patched and whether pr...
therecord.media
April 6, 2026 at 12:28 PM
Although MATCHBOIL was first documented by CERT-UA in August 2025, our research indicates that it has been in development since at least 2024. Our analysis is based on samples from April 2024 to April 2026. 2/7
October 8, 2026 at 4:04 PM
CERT-UA: Fake Cloudflare Checks Deliver LunexStealer Malware securityaffairs.com/200537/hacki...
CERT-UA: Fake Cloudflare Checks Deliver LunexStealer Malware
Over 100 hacked websites used fake Cloudflare checks to trick visitors into installing LunexStealer through ClickFix commands.
securityaffairs.com
October 9, 2026 at 7:42 PM
ClickFix campaign in Ukraine compromises over 100 websites to spread Lunex malware

CERT-UA found fake Cloudflare verification pages that led visitors into a now-familiar ClickFix trap. This time the goal was to infect machines with an infostealer.
ClickFix campaign in Ukraine compromises over 100 websites to spread Lunex malware
CERT-UA found fake Cloudflare verification pages that led visitors into a now-familiar ClickFix trap. This time the goal was to infect machines with an infostealer.
therecord.media
October 6, 2026 at 1:26 PM
CERT-UA Warns of Cyber Scams Using Fake AnyDesk Requests for Fraudulent Security Audits
CERT-UA Warns of Cyber Scams Using Fake AnyDesk Requests for Fraudulent Security Audits
thehackernews.com
January 21, 2025 at 5:57 AM
⚠️ Cyberattack (UAC-0255) disguised as a notification from CERT-UA using the AGEWHEEZE malware (CERT-UA#21075)
cert.gov.ua/article/6288...
CERT-UA
Урядова команда реагування на комп’ютерні надзвичайні події України, яка функціонує в складі Державної служби спеціального зв’язку та захисту інформації України.
cert.gov.ua
March 28, 2026 at 12:01 PM
I bez kouzelné mošničky pomáhají anděl Petronel a čert Uriáš nesobecky dalším. Při dodávce potřebné pomoci na UA nás doprovodil Ivan Trojan a Jiří Dvořák. Mimo jiné vezli sanitku paramedičce Čajce, která díky ní bude moci na předních liniích zachraňovat životy. #viaX Pomozte Ukrajině s Pamětí národa
December 1, 2025 at 7:55 AM
CERT-UA linked UAC-0277 to LunexStealer infections via forged Cloudflare verification pages that trigger ClickFix MSI downloads and EtherHiding-based configuration.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
October 7, 2026 at 7:41 AM
CERT-UA found fake Cloudflare verification pages that led visitors into a now-familiar ClickFix trap. This time the goal was to infect machines with an infostealer therecord.media/clickfix-cam...
ClickFix campaign in Ukraine compromises over 100 websites to spread Lunex malware
CERT-UA found fake Cloudflare verification pages that led visitors into a now-familiar ClickFix trap. This time the goal was to infect machines with an infostealer.
therecord.media
October 6, 2026 at 1:23 PM
Ukraine's Computer Emergency Response Team (CERT-UA) is warning about highly targeted attacks employing compromised Signal accounts to send malware to employees of defense industry firms and members of the country's army forces.
Ukrainian military targeted in new Signal spear-phishing attacks
Ukraine's Computer Emergency Response Team (CERT-UA) is warning about highly targeted attacks employing compromised Signal accounts to send malware to employees of defense industry firms and members of the country's army forces.
www.bleepingcomputer.com
March 19, 2025 at 8:30 PM
VATNIK PHISHING CAMPAIGN TARGETS #UKRAINIANS AND THEIR DEVICES WITH POW EXCHANGE BAIT - UKRAINIAN-CERT (Computer Emergency Response Team) has issued a warning to be extra diligent of attachments in your email.

thehackernews.com/2024/08/cert...
CERT-UA Warns of New Vermin-Linked Phishing Attacks with PoW Bait
CERT-UA warns of new phishing attacks by Vermin hackers, using POW images to spread SPECTR and FIRMACHAGENT malware targeting Ukrainian devices.
thehackernews.com
August 21, 2024 at 10:53 PM
CERT-UA warns UAC-0245 targets Ukraine with CABINETRAT backdoor
CERT-UA warns UAC-0245 targets Ukraine with CABINETRAT backdoor
CERT-UA warns UAC-0245 targets Ukraine with CABINETRAT backdoor via malicious Excel XLL add-ins spotted in Sept 2025.
securityaffairs.com
October 2, 2025 at 6:23 PM
CERT-UA Reports: 11 Ukrainian Telecom Providers Hit by Cyberattacks
CERT-UA Reports: 11 Ukrainian Telecom Providers Hit by Cyberattacks
Ukraine's CERT-UA discovered threat actors targeting 11 telecom providers between May and September 2023. The attacks caused service interruptions.
thehackernews.com
October 17, 2023 at 6:17 AM
CERT-UA Warns of Phishing Attacks Targeting Ukraine’s Defense and Security Force
CERT-UA Warns of Phishing Attacks Targeting Ukraine’s Defense and Security Force
thehackernews.com
December 10, 2024 at 10:13 AM
CERT-UA: Fake Cloudflare Checks Deliver LunexStealer Malware

Over 100 hacked websites used fake Cloudflare checks to trick visitors into installing LunexStealer through ClickFix commands. The lure is the now-familiar ClickFix technique, dressed up as Cloudflare’s standard bot che…
#hackernews #news
CERT-UA: Fake Cloudflare Checks Deliver LunexStealer Malware
Over 100 hacked websites used fake Cloudflare checks to trick visitors into installing LunexStealer through ClickFix commands. The lure is the now-familiar ClickFix technique, dressed up as Cloudflare’s standard bot check. The fake page asks you to run a command, supposedly to confirm you’re not a bot, and that command quietly downloads and installs an […]
securityaffairs.com
October 8, 2026 at 9:45 AM
#650dayofwar

⚡CERT-UA team wins first place at the U.S. Marine Corps Cyber Exercise

#Ukraine #UkraineWar #UkraineRussiaWar
December 5, 2023 at 6:22 PM