ClickFix Lures on Hacked Ukrainian Sites Deliver Psychedelic Stealer and EDR-Blinding LunexStealer
Compromised Ukrainian business sites serve fake Cloudflare ClickFix pages that install Psychedelic Stealer to steal browser credentials and crypto wallets; new Ontinue research now details LunexStealer MaaS using the same lure vector plus AMD driver abuse…
Arctic Wolf Labs documents an active ClickFix campaign in which legitimate Ukrainian business sites were compromised to display fake Cloudflare verification pages. The Hacker News says the lure was injected via a tracker script, while Security Affairs describes hidden iframes serving a Ukrainian-language fake CAPTCHA. Either way, the page copies an msiexec command that victims are told to run with Windows+R (not PowerShell); it fetches MSI installers such as elita.msi from uasputnik[.]com — registered September 9, 2026 per Security Affairs — which then download psychedeliclove.exe (Psychedelic Stealer) from 107.175.82[.]242. The stealer harvests passwords and tokens from Chromium-based browsers (Security Affairs names Chrome, Edge, Brave, Opera, Vivaldi and Yandex) plus cryptocurrency wallets (Exodus, Atomic, Electrum, Bitcoin Core, Litecoin Core); The Hacker News also cites host details. It persists via a scheduled task named psychedelicloveUtils and can retrieve further EXE, script, MSI and PowerShell payloads. Both outlets cite a Rublevka TDS panel with 557 views but disagree on engagement: The Hacker News reports 79 completions (71 from Ukraine) while Security Affairs reports 426 clicks, with 446 of 557 views and 351 clicks from Ukraine. Only The Hacker News notes Arctic Wolf's assessment of likely Russian operators and ClickFix delivery of the RemotePanel and BoundSiphon payloads. Separately, Ontinue (reported by The Hacker News on September 26) details LunexStealer, a Russian-speaking-developed stealer-as-a-service using the same ClickFix fake-CAPTCHA delivery on compromised Ukrainian sites: MSI loaders launch LunexLoader, which bypasses UAC via the CMSTPLUA COM object and performs a BYOVD attack abusing AMD's vulnerable PDFWKRNL.sys driver (CVE-2023-20598) to blind EDR/security processes without killing them. LunexStealer steals credentials from seven Chromium-based browsers, enumerates desktop and browser-extension cryptocurrency wallets, and persists via a Registry Run key, a hidden scheduled task, and a PowerShell-based Chrome Native Messaging Host. Ontinue counts 28 active C2 panels across 13 countries and found that neither HVCI nor Microsoft's Vulnerable Driver Blocklist blocks this driver variant.
- Arctic Wolf Labs attributes the ClickFix campaign to compromised legitimate Ukrainian business sites showing fake Cloudflare verification; The Hacker News describes injection via a tracker script, Security Affairs via hidden iframes with a…
Coverage timelineoldest first · each row is one article
- · 2d agoHacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
The Hacker News· 66
Hacked Ukrainian websites serve fake Cloudflare ClickFix lures that install Psychedelic Stealer to steal credentials and crypto wallets.
- · 1d agoClickFix Campaign Abuses Trusted Websites to Deploy Psychedelic Stealer
Security Affairs· 66
Attackers hijacked Ukrainian sites with a fake Cloudflare CAPTCHA to install Psychedelic Stealer and steal credentials.
- · 15h ago
Vulnerabilities in this storyAll →
- CVE-2023-205987.8<1%An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control over…published · amd radeon software
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-20598 | An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control over… An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control over arbitrary hardware ports or physical addresses resulting in a potential arbitrary code execution. |