Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Malware Stealer Psychedelic




A recent malware campaign has been discovered targeting Ukrainian businesses, using fake Cloudflare verification pages and social engineering tactics to deliver a previously undocumented malware stealer called Psychedelic. The campaign, known as ClickFix, has been found to have a range of capabilities, including the ability to harvest browser passwords, account tokens, and cryptocurrency-wallet data. The malware stealer is designed to be highly stealthy and difficult to detect, and its delivery is initiated through a multi-stage chain of attacks that ultimately leads to the delivery of the malware stealer. This article provides a detailed overview of the ClickFix campaign and the threats it poses to the security of Ukrainian businesses.

  • Malware campaign "ClickFix" targets Ukrainian businesses using fake Cloudflare verification pages.
  • The campaign delivers a previously undocumented malware stealer called Psychedelic, which can harvest browser passwords, account tokens, and cryptocurrency-wallet data.
  • Russian-speaking operators launched the campaign using social engineering and technical tactics to compromise legitimate Ukrainian business websites.
  • The Psychedelic malware stealer is designed to be highly stealthy and difficult to detect, with capabilities to scan for cryptocurrency wallet browser extensions and exfiltrate data through a specific endpoint.
  • The campaign also uses fake Cloudflare verification pages with a Windows Installer command to initiate a multi-stage chain of attacks.
  • Cybersecurity experts warn that the campaign is a major threat to Ukrainian businesses, urging them to take immediate action to protect themselves.
  • The campaign uses a "lure management panel" to monitor the progress of the malware stealer and make adjustments as needed.
  • The campaign also involves the use of a new type of malware called RemotePanel, which provides operators with broad control over infected systems.



  • The world of cybersecurity has been rocked by a recent discovery of a complex and sophisticated malware campaign that has been targeting Ukrainian businesses. The campaign, which has been dubbed "ClickFix," has been found to be serving fake Cloudflare verification pages to trick victims into downloading a previously undocumented malware stealer called Psychedelic. This malware stealer, which has been identified by cybersecurity experts as a major threat to the security of Ukrainian businesses, has been found to have a range of capabilities, including the ability to harvest browser passwords, account tokens, and cryptocurrency-wallet data.

    The ClickFix campaign is believed to have been launched by Russian-speaking operators, who have used a combination of social engineering and technical tactics to compromise legitimate Ukrainian business websites. The campaign has been found to use an "msiexec.exe" command to fetch a Windows MSI installer that is used to deliver the Psychedelic malware stealer. The malware stealer, which is designed to be highly stealthy and difficult to detect, has been found to have a range of capabilities, including the ability to scan for known cryptocurrency wallet browser extensions and desktop apps, and to exfiltrate data through the "/api/v1/ext/wallets" endpoint.

    In addition to the Psychedelic malware stealer, the ClickFix campaign has also been found to be serving fake Cloudflare verification pages that contain a Windows Installer command. This command, which is copied to the clipboard and instructed to be pasted into the Windows Run dialog, is used to initiate a multi-stage chain of attacks that ultimately leads to the delivery of the Psychedelic malware stealer. The campaign has also been found to use a "fsputnik[.]com/tds/tracker[.]js" iframe element to execute attacker-controlled JavaScript, which is used to further compromise the security of the compromised websites.

    Cybersecurity experts have been quick to sound the alarm about the ClickFix campaign, with many warning that the malware stealer is a major threat to the security of Ukrainian businesses. "The Psychedelic stealer is a highly sophisticated and stealthy malware that can harvest a wide range of sensitive data, including browser passwords, account tokens, and cryptocurrency-wallet data," said a cybersecurity expert. "It is a major threat to the security of Ukrainian businesses, and we urge all affected businesses to take immediate action to protect themselves."

    The ClickFix campaign is also notable for its use of a "lure management panel" that is used to configure web-lure commands and record interactions. This panel, which is linked to the "uasputnik[.]com" domain, is used by the attackers to monitor the progress of the malware stealer and to make adjustments to the campaign as needed.

    In addition to the Psychedelic malware stealer, the ClickFix campaign has also been found to be serving fake Cloudflare verification pages that contain a Windows Installer command. This command, which is copied to the clipboard and instructed to be pasted into the Windows Run dialog, is used to initiate a multi-stage chain of attacks that ultimately leads to the delivery of the malware stealer. The campaign has also been found to use a "fsputnik[.]com/tds/tracker[.]js" iframe element to execute attacker-controlled JavaScript, which is used to further compromise the security of the compromised websites.

    The development of the ClickFix campaign is also notable for its use of a new type of malware called RemotePanel, which is a persistent remote access platform that is designed to give operators broad control over infected systems. RemotePanel is also notable for its use of a "BoundSiphon" component, which is a .NET credential and cryptocurrency stealer that targets both Chromium and Firefox browsers.

    Overall, the ClickFix campaign is a major threat to the security of Ukrainian businesses, and we urge all affected businesses to take immediate action to protect themselves. The campaign's use of fake Cloudflare verification pages, social engineering tactics, and advanced malware capabilities make it a highly sophisticated and stealthy threat that can harvest a wide range of sensitive data.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Hacked-Ukrainian-Sites-Serve-Fake-Cloudflare-ClickFix-Lures-for-Malware-Stealer-Psychedelic-ehn.shtml

  • https://thehackernews.com/2026/09/hacked-ukrainian-sites-serve-fake.html


  • Published: Thu Sep 24 11:30:36 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us