ClickFix Campaign Abuses Trusted Websites to Deploy Psychedelic Stealer
Attackers hijacked Ukrainian sites with a fake Cloudflare CAPTCHA to install Psychedelic Stealer and steal credentials.
Arctic Wolf Labs says attackers injected hidden iframes into legitimate Ukrainian business sites to show a Ukrainian-language fake Cloudflare CAPTCHA. Clicking it copies an msiexec command that victims are instructed to run with Windows+R, installing psychedeliclove.exe, tracked as Psychedelic Stealer. The malware steals passwords and tokens from Chrome, Edge, Brave, Opera, Vivaldi and Yandex, plus wallets including Exodus, Atomic, Electrum, Bitcoin Core and Litecoin Core, then persists with scheduled task psychedelicloveUtils and can fetch further payloads. A Rublevka TDS panel recorded 557 views and 426 clicks, mostly from Ukraine; lure domain uasputnik.com was registered on September 9, 2026.