A newly identified information stealer named "Psychedelic" is being distributed through a ClickFix campaign that hijacks legitimate business websites to trick visitors. The attack, detailed in a report by The Hacker News, demonstrates a potent form of social engineering that weaponizes user trust in familiar security protocols.

Attackers are compromising Ukrainian business websites, injecting code that serves fake Cloudflare verification pages to visitors. This common, trust-building interface then instructs the user to copy a Windows Installer command and paste it into their system's command prompt to "verify" their browser.

This technique is known as ClickFix. It shifts the attack from a phishing link to an interactive, in-session prompt that manipulates the user's own actions to execute the malware. Once pasted and run, the command downloads and installs the previously undocumented Psychedelic stealer, which is designed to exfiltrate sensitive data such as credentials, cryptocurrency wallets, and browser cookies.

The campaign's effectiveness hinges on abusing the reputation of compromised, legitimate domains. This allows the malicious pages to bypass traditional security filters that block known bad URLs. The familiar Cloudflare branding further lowers user suspicion, making the unusual request to paste a command seem like a plausible step.

This incident is a critical case study for defenders. It highlights the need for robust technical controls, including file integrity monitoring and anomaly detection on public-facing web servers, to quickly spot unauthorized content injections. Regular access log reviews can also help identify signs of a compromise.

Equally important is updating the human layer of defense. User training must now address social engineering that occurs beyond the inbox. Employees should be taught to treat any webpage, no matter how legitimate it appears, that instructs them to copy and paste commands into a terminal like PowerShell or Command Prompt as an immediate red flag. Clear procedures for reporting such incidents without interaction are essential.

The emergence of the Psychedelic stealer is another reminder of the continuous development of malware by threat actors. While full technical analysis is ongoing, the method of exploiting trust via ClickFix on legitimate sites is a known and growing threat. The initial compromise vector for the Ukrainian sites remains unclear, but vulnerabilities in content management systems or weak admin credentials are common entry points.

Ultimately, this campaign underscores a shift where sophisticated attackers subvert the user's own actions within a trusted environment. Defending against this requires both vigilant technical monitoring and a cultivated skepticism among users.


一種名為「迷幻」(Psychedelic)的新型信息竊取惡意軟件,正透過名為ClickFix的攻擊活動傳播。該活動劫持合法商業網站來欺騙訪客。據《黑客新聞》(The Hacker News)報導詳述的攻擊,展示了一種利用用戶對熟悉安全機制信任的強大社會工程學手段。

攻擊者入侵烏克蘭商業網站,注入偽造的 Cloudflare 驗證頁面代碼予訪客。此常見且具信賴感的界面隨後指示用戶複製一條 Windows Installer 指令,並將其貼上系統的命令提示字元,以「驗證」其瀏覽器。

此技術被稱為ClickFix。它將攻擊從釣魚連結轉變為互動式、即時的提示,利用用戶自身操作來執行惡意軟件。指令一旦被貼上並運行,便會下載並安裝先前未被記錄的「迷幻」竊取器,該軟件旨在竊取敏感資料,如憑證、加密貨幣錢包及瀏覽器 Cookies。

該攻擊活動的有效性,在於濫用被入侵的合法網域信譽。這使得惡意網頁能繞過封鎖已知惡意網址的傳統安全過濾器。熟悉的 Cloudflare 品牌進一步降低用戶戒心,使得複製指令這種不尋常的要求看似合理步驟。

此事件是防禦者的關鍵案例研究。它凸顯了建立強健技術控制的必要性,包括檔案完整性監控及對外公開網絡伺服器的異常檢測,以迅速偵測未經授權的內容注入。定期審查存取日誌亦有助於識別入侵跡象。

同樣重要的是更新人類防禦層面。用戶培訓現必須涵蓋發生在電郵收件匣之外的社會工程學手段。應教導員工將任何網頁——無論其外觀多麼合法——只要指示他們複製並貼上指令到 PowerShell 或命令提示字元等終端機,視為立即亮起的紅燈。制訂清晰的匯報程序以處理此類事件,且不進行互動,至關重要。

「迷幻」竊取器的出現,再次提醒威脅行為者持續開發惡意軟件。儘管全面的技術分析仍在進行中,但透過ClickFix在合法網站上利用信任的攻擊方法,已是一項眾所周知且日益增長的威脅。烏克蘭網站的初始入侵途徑尚不清楚,但內容管理系統漏洞或薄弱的管理員憑證是常見的入侵點。

總括而言,此攻擊活動突顯了一種轉變:老練的攻擊者在可信環境中,顛覆用戶自身的操作。防禦此類攻擊,需要結合警覺的技術監控與用戶培養出的質疑態度。

新聞來源 / Original News Source