DKDKCISSPSearch
Cloud & Identity

Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic .

DKCISSP News DeskThe Hacker News26 Sept 2026, 11:53 pm
Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic .

The ClickFix chain uses an "msiexec.exe" command to fetch a Windows MSI installer that's used to deliver the stealer malware.

The process then proceeds to configure broad Microsoft Defender exclusions and fetch and execute two more payloads using different methods - The campaign has not been attributed to any known threat actor or group, although Blackpoint said it recovered artifacts that suggest a possible Russian-speaking development environment.

Arctic Wolf said it identified an exposed lure management panel linked to the campaign called РУБЛЁВКА TDS (Rublevka TDS) on the "uasputnik[.]com" domain.

The malicious tool is designed to harvest browser passwords, account tokens, and cryptocurrency-wallet data, set up scheduled-task persistence, and contact a command-and-control (C2) server for more tasking.

The attack sequence begins with a ClickFix command that uses PowerShell to initiate a multi-stage chain, with one of the intermediate components abusing the CMSTPLUA COM object to bypass User Account Control (UAC) and gain elevated administrative privileges without prompting the user and run a privileged hidden PowerShell process.

After a three-second spinner, the page presents an instruction dialog and keeps the 'Done' button disabled for about 35 more seconds." "This delay controls progression through the lure interface; it does not verify that the visitor opened Windows Run, pasted the command, or installed the payload." The MSI installer, for its part, is responsible for retrieving the next-stage payload ("psychedeliclove.exe") from the URL "107.175.82[.]242:9000." The 64-bit Windows executable is Psychedelic Stealer, which performs the following functions - "These components extend the operation beyond one-time data collection," Arctic Wolf said.

The development comes as Blackpoint Cyber said it identified two undocumented .NET malware components delivered together via a ClickFix chain: RemotePanel , a persistent remote access platform, and BoundSiphon , a .NET credential and cryptocurrency stealer that targets both Chromium and Firefox browsers.

Other MSI payloads identified include "miks.msi," "astra.msi," "harbor.msi," "neon.msi," "sova.msi," and "vyse.msi." "The attacker-controlled page imitates a Cloudflare verification screen and presents Ukrainian-language instructions," Arctic Wolf said.

It can allow the malware to run EXE, COM, BAT, CMD, MSI, and PowerShell payloads, offering the operator a way to introduce more malware.

What happened

An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic .

The ClickFix chain uses an "msiexec.exe" command to fetch a Windows MSI installer that's used to deliver the stealer malware.

What changed

The process then proceeds to configure broad Microsoft Defender exclusions and fetch and execute two more payloads using different methods - The campaign has not been attributed to any known threat actor or group, although Blackpoint said it recovered artifacts that suggest a possible Russian-speaking development environment.

Arctic Wolf said it identified an exposed lure management panel linked to the campaign called РУБЛЁВКА TDS (Rublevka TDS) on the "uasputnik[.]com" domain.

Who is affected

The malicious tool is designed to harvest browser passwords, account tokens, and cryptocurrency-wallet data, set up scheduled-task persistence, and contact a command-and-control (C2) server for more tasking.

The attack sequence begins with a ClickFix command that uses PowerShell to initiate a multi-stage chain, with one of the intermediate components abusing the CMSTPLUA COM object to bypass User Account Control (UAC) and gain elevated administrative privileges without prompting the user and run a privileged hidden PowerShell process.

Why it matters

After a three-second spinner, the page presents an instruction dialog and keeps the 'Done' button disabled for about 35 more seconds." "This delay controls progression through the lure interface; it does not verify that the visitor opened Windows Run, pasted the command, or installed the payload." The MSI installer, for its part, is responsible for retrieving the next-stage payload ("psychedeliclove.exe") from the URL "107.175.82[.]242:9000." The 64-bit Windows executable is Psychedelic Stealer, which performs the following functions - "These components extend the operation beyond one-time data collection," Arctic Wolf said.

The development comes as Blackpoint Cyber said it identified two undocumented .NET malware components delivered together via a ClickFix chain: RemotePanel , a persistent remote access platform, and BoundSiphon , a .NET credential and cryptocurrency stealer that targets both Chromium and Firefox browsers.

Technical details

Other MSI payloads identified include "miks.msi," "astra.msi," "harbor.msi," "neon.msi," "sova.msi," and "vyse.msi." "The attacker-controlled page imitates a Cloudflare verification screen and presents Ukrainian-language instructions," Arctic Wolf said.

It can allow the malware to run EXE, COM, BAT, CMD, MSI, and PowerShell payloads, offering the operator a way to introduce more malware.

The ClickFix command, for its part, retrieves an MSI installer ("elita.msi") hosted on "uasputnik[.]com," a domain that was registered on September 9, 2026.

Response

This includes source code checks to avoid executing on systems with a Russian keyboard layout.

Attribution

The Hacker News: An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic .

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

Watch for updated vendor guidance and fixed-version details.