Ethical Hacking News
A sophisticated malware campaign has been discovered that exploits browser and crypto credentials through compromised Ukrainian websites. The malware, called Psychedelic Stealer, steals saved passwords from browsers and cryptocurrency wallets, and uses a fake Cloudflare CAPTCHA to trick visitors into installing the malware. The campaign targets Ukrainian-language websites and uses a management panel to control the malware's behavior. Defenders should monitor network traffic and investigate indicators to detect and prevent the attack.
Malware called Psychedelic Stealer is being distributed through compromised Ukrainian business websites. The malware steals browser and crypto credentials, including saved passwords and cryptocurrency wallets. The attack uses a fake Cloudflare CAPTCHA to trick visitors into installing the malware. The malware targets saved passwords from browsers, browser account tokens, and cryptocurrency wallets. The attackers use a management panel called "РУБЛЁВКА TDS" to control the malware and track victim interactions. The campaign targets Ukraine, with over 446 views and 351 clicks coming from Ukrainian-language instructions and websites. Defenders can monitor network traffic to uasputnik[.]com, admin777111777.php, and 193.178.159[.]128:8080 to detect early and later stages of the attack.
In a sophisticated and complex attack, hackers have compromised multiple Ukrainian websites, including legitimate businesses with established social media profiles and third-party listings, to deploy a malware called Psychedelic Stealer. The malware, which is being distributed through compromised Ukrainian business websites, steals browser and crypto credentials, including saved passwords from browsers such as Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Yandex, as well as cryptocurrency wallets, including Exodus, Atomic Wallet, Electrum, Bitcoin Core, and Litecoin Core.
The attack uses a fake Cloudflare CAPTCHA to trick visitors into installing the malware. The fake CAPTCHA is designed to look like a legitimate verification screen, with a randomly generated "Ray ID" and a fixed "visitor identifier" that imitates familiar verification and tracking elements. The page is written in Ukrainian, which fits the target audience, but its HTML carries Russian-language comments and the document declares lang="ru", a detail that tells you something about who built it even if it doesn't confirm nationality or location.
When the victim clicks the fake CAPTCHA, the page silently copies a Windows Installer command to the clipboard. It then tells the user to press Windows+R, paste the command, and press Enter. The downloaded MSI file then installs a 64-bit executable called psychedeliclove.exe, which is tracked as Psychedelic Stealer. The malware targets saved passwords from browsers, as well as browser account tokens and cryptocurrency wallets.
The implant also installs browser components and sets up a native messaging bridge that lets deployed browser content communicate with a local process on the machine. It creates a scheduled task for persistence named psychedelicloveUtils, profiles the host in detail including antivirus status and installed browsers, and then starts polling its command-and-control server for additional tasks.
The campaign also uses a management panel called "РУБЛЁВКА TDS" (Rublevka TDS), a name referring to the wealthy Rublevka area near Moscow. The panel allows the attackers to control the Windows Installer command delivered by each compromised website. This means they can change the payload URL from one place without modifying every infected page.
The panel also tracks how visitors interact with the fake CAPTCHA. It records when the page is opened, when the CAPTCHA is clicked, and when the user presses the Done button. The Done button remains disabled for about 35 seconds after the command is copied. The delay has no technical purpose. It simply gives victims enough time to follow the instructions and run the command, adding another layer of social engineering to the attack.
At collection time, the panel showed 557 views, 426 clicks, and 79 complete events across 32 countries. Ukraine accounted for 446 of those views and 351 of the clicks, which combined with Ukrainian-language instructions and Ukrainian business websites makes the targeting intent about as clear as it gets.
The domain at the center of this, uasputnik[.]com, was registered on September 9, 2026, updated three and a half hours later, and associated with lure URLs appearing on September 12 and 13. The whole operational window from registration to observed delivery fits inside a week.
For defenders, there are several useful indicators to monitor. Network traffic to uasputnik[.]com, followed by a request to admin777111777.php, could indicate an early stage of the attack. A later-stage sign is traffic to 193.178.159[.]128:8080, particularly requests to /api/v1/agent/ and /api/v1/ext/ with an X-API-Key header.
These indicators should be investigated together with file creation and process execution events to confirm whether a system has been compromised.
Related Information:
https://www.ethicalhackingnews.com/articles/ClickFix-Campaign-Abuses-Trusted-Websites-to-Deploy-Psychedelic-Stealer-A-Sophisticated-Malware-that-Exploits-Browser-and-Crypto-Credentials-ehn.shtml
https://securityaffairs.com/199731/malware/clickfix-campaign-abuses-trusted-websites-to-deploy-psychedelic-stealer.html
Published: Fri Sep 25 10:35:09 2026 by llama3.2 3B Q4_K_M