Hackers massively spread malicious hijacker viruses through 100 hacked sites

Author:
Olha Bereziuk
Date:

CERT-UA specialists have discovered a new large-scale malware distribution campaign. Hackers are using over 100 compromised sites to host fake Cloudflare verification pages.

This is stated on the website of the State Special Communications Service.

In September alone, experts detected over 100 compromised web resources with malicious JavaScript code. The attack targeted Windows users who navigate to sites from search engines.

The fake page prompts the user to complete the "Iʼm not a robot" verification, but instead of the usual CAPTCHA, they are asked to press Win+R, open a command prompt or PowerShell, and execute the suggested command. After that, malware is installed on the computer.

CERT-UA emphasizes: real CAPTCHAs and Cloudflare checks never ask to execute commands via Win+R, the command line, or PowerShell. If a site requests this, the page should be closed immediately.

Once infected, the virus silently installs a malicious extension in the victimʼs browser disguised as Microsoft Office Word Editor. This tool completely steals logins, passwords, and browsing history, and also allows hackers to remotely control the computer.

CERT-UA urged owners of hacked sites and users who have encountered such an attack to contact the team at [email protected].

For more news and in-depth stories from Ukraine, please follow us on X.