A recent cyberattack campaign has been detected targeting legitimate Ukrainian business websites to distribute a newly discovered information stealer called Psychedelic. This operation, known as ClickFix, involves the manipulation of authentic sites to display counterfeit Cloudflare verification pages, misleading users into downloading the malicious software.
The Mechanism of Infection
Upon interacting with these deceptive pages, users are tricked into copying a Windows Installer command to their clipboard and executing it in the Windows Run dialog. This process, explained by Arctic Wolf Labs in a technical report, utilizes the ‘msiexec.exe’ command to download a Windows MSI installer, which then deploys the Psychedelic malware.
The malware is programmed to extract sensitive data such as browser passwords, account tokens, and cryptocurrency wallet information. Additionally, it establishes persistence by configuring scheduled tasks and communicates with a command-and-control server to receive further instructions.
Targeted Websites and Payloads
The compromised websites span various industries, including a hair-treatment clinic, book publisher, and automotive retailer. These sites contain an injected iframe element that executes attacker-controlled JavaScript from the domain “fsputnik[.]com”.
The main payload, an MSI installer named “elita.msi,” is hosted on “uasputnik[.]com,” a domain registered in September 2026. Other identified MSI payloads include “miks.msi,” “astra.msi,” and “neon.msi.” The attacker-controlled verification page mimics Cloudflare and employs a delayed dialog to manipulate user actions.
Advanced Capabilities of Psychedelic Stealer
The Psychedelic Stealer is advanced, capable of collecting credentials from various Chromium-based browsers and exfiltrating the data through specific API endpoints. It targets cryptocurrency wallet extensions and desktop applications, capturing extensive host information and altering browser profiles for sustained data extraction.
Furthermore, the malware can execute additional tasks using various payload forms, enhancing its ability to deploy further malicious software. The campaign’s management panel, identified as РУБЛЁВКА TDS, records interaction metrics, with a significant focus on Ukrainian users.
Additional Findings and Implications
In a related development, Blackpoint Cyber revealed two undocumented .NET malware components associated with the ClickFix chain: RemotePanel and BoundSiphon. RemotePanel provides persistent remote access and control, while BoundSiphon focuses on credential and cryptocurrency theft.
These components indicate a shift towards modular malware ecosystems, allowing operators to maintain persistent access while adapting infrastructure. RemotePanel utilizes a BNB Smart Chain contract for dynamic C2 server resolution, and BoundSiphon integrates into legitimate browser processes to capture sensitive information.
The sophistication of these attacks underscores the importance of vigilance and advanced detection mechanisms to protect against evolving cyber threats. The campaign’s unconfirmed attribution to any specific group does not diminish the potential risks posed to Ukrainian businesses and beyond.
