Fairfield, NJ · Metro New York (888) 711-4521 Founded 2013 · Metro New York
← All Insights
Close-up of a smartphone screen displaying account verification alert. Ideal for security and authenticity themes.
Threat Intelligence

That 'Prove You're Human' Pop-Up May Be Stealing Your Passwords Right Now

Picture this: someone on your team is Googling a vendor name or an industry question. They click a result, land on what looks like a normal website, and immediately see a familiar gray Cloudflare box — the kind that normally just spins for a second and then lets you through. Except this one asks them to prove they're human by following a few extra steps. They do. And quietly, in the background, a piece of malware installs itself and starts vacuuming up every saved password, cookie, and login token in their browser.

That is not a hypothetical. It is the exact attack that Ukraine's Computer Emergency Response Team, known as CERT-UA, disclosed this week after identifying the campaign in September 2026.

What CERT-UA Found

CERT-UA identified more than 100 compromised websites — legitimate sites whose owners had no idea anything was wrong — that had been injected with malicious code designed to display a forged Cloudflare verification page. The malware delivered is called LunexStealer (also tracked as Psychedelic Stealer), and it is an information-stealing program that harvests credentials and accepts remote commands from the attacker.

The technique powering the attack is called ClickFix. Rather than asking you to download a file — which most people know to be suspicious — it asks you to run a command. Specifically, it instructs you to press the Windows key and R together to open the Windows Run dialog, paste a string of text from your clipboard, and hit Enter. That pasted text is the attack. It installs a malicious Microsoft Software Installer (MSI) package from a server the attackers control.

The deception is well-constructed. The fake page appears only to Windows users who arrive through a search engine — Google, DuckDuckGo, and others — and it shows the fake prompt no more than twice in a 12-hour window for the same visitor. That selective targeting keeps the campaign quiet and makes it harder for security researchers to detect by simply revisiting the same URL.

The Blockchain Twist That Makes This Harder to Shut Down

Here is where it gets more sophisticated. The attackers store the address of their fake verification page inside a smart contract on the Polygon or Ethereum blockchain. The malicious script on the compromised website checks that contract each time it runs. This means the attackers can change their delivery address, or switch the attack on and off entirely, without ever touching the hacked sites again. Security researchers call this technique EtherHiding. In plain English: the usual approach of blocking a single malicious domain is not enough, because the attackers can simply update the contract and use a new one.

The script has three modes: fully off, silent visitor tracking, and the full fake verification page. Attackers can toggle between them remotely. It is, effectively, a remote-controlled trap embedded inside websites that look completely normal to their owners and to any casual visitor.

What Gets Stolen — and What Comes Next

LunexStealer does not just grab one password and leave. Once installed, it also deploys a malicious browser extension called LUNARAXE that can give attackers ongoing remote control of the victim's browser. That means they can read whatever is open in the browser, capture logins as they happen, and potentially access business banking portals, your accounting software, your payroll provider, or your email — even after the initial stolen session tokens expire.

For a small business, this is the data that gets pulled: saved browser passwords, session cookies for cloud apps, anything auto-filled in forms. One compromised laptop belonging to someone with administrator access to your business systems can cascade into a much larger incident.

Honest Severity Read

CERT-UA has not confirmed the number of successful infections, and the campaign as reported was concentrated on Ukrainian-language sites. However, ClickFix as a delivery method is not new and is not region-specific. Security researchers at BleepingComputer confirmed a separate but nearly identical campaign — using the same fake Cloudflare CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart) and the same Windows Run dialog trick — running on English-language infrastructure within the past two weeks. The technique works because it looks like something millions of people see every day. That familiarity is the vulnerability.

The risk is real and rising. It does not require your team to do anything that sounds dangerous. It just requires them to follow what look like normal on-screen instructions on a website they may have visited a dozen times before.

A Quick Note on Third-Party Risk This Month

This ClickFix campaign is not the only active threat worth mentioning this week. Separately, Google's Threat Intelligence Group confirmed on September 28 that the extortion group ShinyHunters is running a new campaign against Oracle PeopleSoft systems — the software large employers, universities, and healthcare systems use to manage payroll and benefits. If your business works with, or is employed by, a larger organization that runs PeopleSoft for Human Resources (HR) or payroll, your employee data — Social Security numbers, bank details, salary records — may be at elevated risk through no fault of your own. That is the definition of third-party risk: someone else's unpatched software becomes your problem.

So What Does This Mean for My Business, and What Do I Do?

You do not need to become a technical expert. But you do need to have a direct conversation with whoever manages your IT or cybersecurity. Here are the specific questions to ask:

  • "Are our Windows computers configured so that regular employees cannot open the Windows Run dialog or install software without administrator approval?" CERT-UA's own guidance recommends restricting user-driven command execution as the primary defense against ClickFix. This is a policy setting, not a purchase.
  • "Do we have a list of approved browser extensions, and are employees blocked from installing unapproved ones?" LunexStealer installs a malicious browser extension as a secondary payload. An extension allowlist stops that step cold.
  • "Are we monitoring for software installation attempts that include web addresses (URLs) in the command?" That is the specific technical signature of a ClickFix attack landing on a machine.
  • "Which of our payroll, benefits, or HR functions run through a third-party provider, and have any of those providers disclosed a breach or issued a security advisory in the last 90 days?" This covers your exposure through the PeopleSoft situation and any similar vendor-side risk.

And one thing you can tell every person in your business right now, no IT background required: a real security check — from Cloudflare, from Windows, from anyone — will never ask you to open a command window and paste something into it. If a webpage asks you to do that, close the browser tab. Full stop.

CERT-UA put it simply: legitimate verification never requires executing commands. That one sentence, shared in a team meeting or a quick Slack message, is worth more than most security tools you could buy this week.

Sources

Secured by IA