Threat Intelligence

Fake Cloudflare Checks on Hacked Ukrainian Sites Spread New "Psychedelic" Stealer Malware

The Hacker News · 25 Sept 2026
Key Takeaway Train staff to never copy and paste commands into the Windows Run dialog based on a website prompt, no matter how official the page looks, and treat any such request as a red flag.

Security researchers at Arctic Wolf Labs have uncovered an active campaign using the ClickFix technique on compromised Ukrainian business websites, including a hair-treatment clinic, a bookseller, and an automotive retailer. Victims are shown a fake Cloudflare verification page that copies a malicious command to their clipboard and instructs them to paste it into the Windows Run dialog, a trick designed to bypass normal security warnings by getting the user to run the attack themselves.

Once executed, the command downloads a Windows installer file that delivers a previously undocumented stealer malware dubbed Psychedelic. This malware harvests browser-saved passwords, account login tokens, and cryptocurrency wallet data, then sets up scheduled tasks so it can persist on the infected machine and contact a remote server for further instructions. Researchers noted the fake verification page uses a timed delay to appear legitimate, though it does not actually confirm whether the victim followed the instructions.

The use of legitimate, hacked websites to host these lures makes the campaign harder to spot through normal blocklists, since the domains themselves may otherwise appear trustworthy.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.