Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
Hacked Ukrainian websites serve fake Cloudflare ClickFix lures that install Psychedelic Stealer to steal credentials and crypto wallets.
Arctic Wolf Labs says an active ClickFix campaign compromised legitimate Ukrainian business sites and injected fake Cloudflare verification pages. The lure copies an msiexec command that fetches MSI installers from uasputnik[.]com, which then download psychedeliclove.exe, Psychedelic Stealer, from 107.175.82[.]242. The stealer collects Chromium passwords and tokens, cryptocurrency wallet data, and host details, persists via scheduled tasks, and can retrieve further payloads. A Rublevka TDS panel recorded 557 views and 79 completions, mostly in Ukraine; Arctic Wolf assesses likely Russian operators. The same reporting notes ClickFix delivery of RemotePanel and BoundSiphon.