By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Ukrainian Sites Host Fake Cloudflare Pages for Psychedelic Stealer

A sophisticated cyberattack campaign, identified as ClickFix, is actively compromising legitimate Ukrainian business websites to distribute a novel information stealer malware named Psychedelic. The attackers are injecting deceptive Cloudflare verification pages onto these compromised sites. These fake pages are designed to mimic legitimate security checks, tricking unsuspecting visitors into downloading the malicious software. When a user interacts with the fraudulent verification page, the campaign executes a Windows Installer command, copying it to the user's clipboard. The lure then instructs the victim to paste this command into their system, thereby initiating the download and execution of the Psychedelic stealer.
This particular campaign leverages the trust users place in established brands like Cloudflare, a widely used content delivery network and security service provider. By impersonating Cloudflare, the attackers aim to bypass user skepticism and encourage the execution of malicious commands. The Psychedelic stealer itself is a previously undocumented piece of malware, suggesting a new or evolving threat actor group. Information stealers are a type of malware designed to exfiltrate sensitive data from infected systems, including login credentials, financial information, and personal data. The specific capabilities and targets of the Psychedelic stealer are still under investigation, but its distribution method indicates a focus on broad compromise of users visiting the affected Ukrainian websites.
The compromise of legitimate business websites in Ukraine highlights a concerning trend where attackers exploit trusted online infrastructure for malicious purposes. This tactic not only broadens the attack surface but also makes it more difficult for security professionals to distinguish between legitimate traffic and malicious activity. The use of Windows Installer commands suggests a targeted approach to exploit vulnerabilities or features within the Windows operating system. The ClickFix campaign's reliance on social engineering, specifically through the impersonation of a well-known security service, underscores the importance of user education and robust endpoint security measures. Security researchers are actively analyzing the malware and the campaign's infrastructure to understand the full scope of the threat and to develop countermeasures. The Ukrainian cybersecurity landscape remains a target, and such attacks underscore the ongoing need for vigilance and advanced threat detection capabilities.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.