Fake Cloudflare Checks on Hacked Ukrainian Sites Spread New "Psychedelic" Stealer Malware
Security researchers at Arctic Wolf Labs have uncovered an active campaign using the ClickFix technique on compromised Ukrainian business websites, including a hair-treatment clinic, a bookseller, and an automotive retailer. Victims are shown a fake Cloudflare verification page that copies a malicious command to their clipboard and instructs them to paste it into the Windows Run dialog, a trick designed to bypass normal security warnings by getting the user to run the attack themselves.
Once executed, the command downloads a Windows installer file that delivers a previously undocumented stealer malware dubbed Psychedelic. This malware harvests browser-saved passwords, account login tokens, and cryptocurrency wallet data, then sets up scheduled tasks so it can persist on the infected machine and contact a remote server for further instructions. Researchers noted the fake verification page uses a timed delay to appear legitimate, though it does not actually confirm whether the victim followed the instructions.
The use of legitimate, hacked websites to host these lures makes the campaign harder to spot through normal blocklists, since the domains themselves may otherwise appear trustworthy.