Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Ukrainian Sites Hacked for Psychedelic Stealer Distribution

Ukrainian Sites Hacked for Psychedelic Stealer Distribution

Posted on September 24, 2026 By CWS

A recent cyberattack campaign has been detected targeting legitimate Ukrainian business websites to distribute a newly discovered information stealer called Psychedelic. This operation, known as ClickFix, involves the manipulation of authentic sites to display counterfeit Cloudflare verification pages, misleading users into downloading the malicious software.

The Mechanism of Infection

Upon interacting with these deceptive pages, users are tricked into copying a Windows Installer command to their clipboard and executing it in the Windows Run dialog. This process, explained by Arctic Wolf Labs in a technical report, utilizes the ‘msiexec.exe’ command to download a Windows MSI installer, which then deploys the Psychedelic malware.

The malware is programmed to extract sensitive data such as browser passwords, account tokens, and cryptocurrency wallet information. Additionally, it establishes persistence by configuring scheduled tasks and communicates with a command-and-control server to receive further instructions.

Targeted Websites and Payloads

The compromised websites span various industries, including a hair-treatment clinic, book publisher, and automotive retailer. These sites contain an injected iframe element that executes attacker-controlled JavaScript from the domain “fsputnik[.]com”.

The main payload, an MSI installer named “elita.msi,” is hosted on “uasputnik[.]com,” a domain registered in September 2026. Other identified MSI payloads include “miks.msi,” “astra.msi,” and “neon.msi.” The attacker-controlled verification page mimics Cloudflare and employs a delayed dialog to manipulate user actions.

Advanced Capabilities of Psychedelic Stealer

The Psychedelic Stealer is advanced, capable of collecting credentials from various Chromium-based browsers and exfiltrating the data through specific API endpoints. It targets cryptocurrency wallet extensions and desktop applications, capturing extensive host information and altering browser profiles for sustained data extraction.

Furthermore, the malware can execute additional tasks using various payload forms, enhancing its ability to deploy further malicious software. The campaign’s management panel, identified as РУБЛЁВКА TDS, records interaction metrics, with a significant focus on Ukrainian users.

Additional Findings and Implications

In a related development, Blackpoint Cyber revealed two undocumented .NET malware components associated with the ClickFix chain: RemotePanel and BoundSiphon. RemotePanel provides persistent remote access and control, while BoundSiphon focuses on credential and cryptocurrency theft.

These components indicate a shift towards modular malware ecosystems, allowing operators to maintain persistent access while adapting infrastructure. RemotePanel utilizes a BNB Smart Chain contract for dynamic C2 server resolution, and BoundSiphon integrates into legitimate browser processes to capture sensitive information.

The sophistication of these attacks underscores the importance of vigilance and advanced detection mechanisms to protect against evolving cyber threats. The campaign’s unconfirmed attribution to any specific group does not diminish the potential risks posed to Ukrainian businesses and beyond.

The Hacker News Tags:Arctic Wolf, Blackpoint Cyber, BoundSiphon, ClickFix, Cloudflare scam, Cybersecurity, Malware, Psychedelic Stealer, RemotePanel, Ukrainian websites

Post navigation

Previous Post: Konni Malware Campaign Targets Ukrainian Entities with Fake PDFs
Next Post: AI Agents Exploit Websites for Data Collection Concerns

Related Posts

AI-Powered Zero-Day Exploit Bypasses 2FA Security AI-Powered Zero-Day Exploit Bypasses 2FA Security The Hacker News
CSS Vulnerabilities Threaten Webmail Security CSS Vulnerabilities Threaten Webmail Security The Hacker News
Microsoft Links Ongoing SharePoint Exploits to Three Chinese Hacker Groups Microsoft Links Ongoing SharePoint Exploits to Three Chinese Hacker Groups The Hacker News
Researchers Uncover Chrome Extensions Abusing Affiliate Links and Stealing ChatGPT Access Researchers Uncover Chrome Extensions Abusing Affiliate Links and Stealing ChatGPT Access The Hacker News
RatOn Android Malware Detected With NFC Relay and ATS Banking Fraud Capabilities RatOn Android Malware Detected With NFC Relay and ATS Banking Fraud Capabilities The Hacker News
Breaches Hidden, Attack Surfaces Growing, and AI Misperceptions Rising Breaches Hidden, Attack Surfaces Growing, and AI Misperceptions Rising The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Agents Exploit Websites for Data Collection Concerns
  • Ukrainian Sites Hacked for Psychedelic Stealer Distribution
  • Konni Malware Campaign Targets Ukrainian Entities with Fake PDFs
  • Agentic Remediation: Closing the Loop in Cybersecurity
  • WordPress Security Flaw CVE-2026-87902 Under Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Agents Exploit Websites for Data Collection Concerns
  • Ukrainian Sites Hacked for Psychedelic Stealer Distribution
  • Konni Malware Campaign Targets Ukrainian Entities with Fake PDFs
  • Agentic Remediation: Closing the Loop in Cybersecurity
  • WordPress Security Flaw CVE-2026-87902 Under Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark