A new wave of the ClickFix social engineering tactic is actively hijacking legitimate Ukrainian business websites to trick visitors into installing a previously undocumented information stealer named "Psychedelic." The campaign represents a calculated evolution in attacker methodology, weaponizing trust in familiar domains to bypass user skepticism and deliver malware through a novel infection chain.

According to analysis reported by The Hacker News, attackers have compromised several authentic Ukrainian company websites. Instead of their normal content, visitors are now served fake Cloudflare security verification pages. These lures present a simple, familiar challenge: "prove you are not a robot" by completing a quick manual task.

The Mechanics of a User-Driven Attack

The attack's potency lies in the ClickFix method, which cleverly shifts the final execution step to the victim. When a user interacts with the fraudulent page—typically by clicking a button—a malicious PowerShell command is silently copied to their clipboard. The page then displays a final prompt, instructing the visitor to open a command interface, paste the clipboard contents, and press Enter.

This pasted command downloads and executes the Psychedelic stealer. By having the victim manually initiate the final step, the campaign can evade many security tools designed to detect automated drive-by downloads or browser-based exploits. The malicious activity originates from a user-initiated action on a trusted domain, making it a particularly effective evasion tactic.

Weaponizing Trust: The Strategy of Compromised Legitimacy

The choice to compromise authentic business websites is a strategic force multiplier. Users are inherently more inclined to trust a familiar corporate domain than an unfamiliar, suspiciously named one. This inherent trust makes them more susceptible to following on-screen instructions, even when those instructions involve unusual technical steps.

The report notes that the specific Ukrainian sites targeted were real, operating businesses, lending powerful credibility to the fake Cloudflare lures hosted upon them. This approach transforms a routine website visit into a potential security incident, demonstrating that vigilance cannot be relaxed even when browsing seemingly reputable online properties.

Inside the Psychedelic Stealer

Once installed, the Psychedelic stealer begins exfiltrating data from the infected machine. While a complete technical teardown was not available at the time of reporting, information stealers typically target sensitive data such as saved browser credentials, cryptocurrency wallet files, and session cookies for various online services.

The campaign's use of a newly dubbed malware family suggests either a new tool in development or one that has recently entered the cybercriminal ecosystem. This lack of prior exposure may allow it to bypass signature-based detection for a period as security vendors work to develop and distribute protective signatures.

Building a Layered Defense

Defending against this type of attack requires parallel action on multiple fronts. The campaign highlights three critical defensive imperatives for IT teams:

  1. Harden Web Assets to Prevent Initial Compromise: The attack begins with the compromise of legitimate websites. Organizations must prioritize web application security through rigorous patching, secure coding practices, and regular security audits to prevent their online properties from being hijacked and weaponized as lures.

  2. Enhance Endpoint Monitoring for User-Initiated Activity: The ClickFix technique relies on the victim pasting and executing a command. Security teams should configure endpoint detection and response (EDR) solutions to closely monitor and alert on suspicious user-initiated activities, such as unexpected PowerShell execution or command prompt usage, which are key indicators of this attack chain.

  3. Continuous User Training to Recognize Social Engineering: Users are the final and most critical link in the attack chain. Ongoing security awareness training is essential, specifically focusing on social engineering tactics like ClickFix. Employees must be educated to question and resist prompts that ask them to manually execute commands, even when presented on trusted websites.

The ongoing evolution of social engineering, combined with the exploitation of trusted infrastructure, remains a potent threat. This campaign serves as a clear reminder that a resilient defense posture is built on both robust technical controls and a well-informed human layer.


新一波ClickFix社交工程攻擊手段正積極劫持合法的烏克蘭商業網站,欺騙訪客安裝名為「Psychedelic」的未知竊取程式。此攻擊行動代表攻擊者策略的刻意演進,利用對熟悉網域的信任規避用戶警惕,並透過新型感染鏈傳播惡意軟件。

根據The Hacker News報導的分析,攻擊者已入侵多個真實的烏克蘭公司網站。訪客現在看到的並非正常內容,而是偽造的Cloudflare安全驗證頁面。這些誘餌提供簡單而熟悉的挑戰:透過快速手動任務「證明你並非機器人」。

用戶驅動式攻擊的運作機制

攻擊的威力在於ClickFix方法,其巧妙地將最終執行步驟轉移給受害者。當用戶與詐騙頁面互動(通常是點擊按鈕)時,惡意PowerShell指令會靜默複製到其剪貼簿。頁面隨後顯示最終提示,指示訪問者開啟命令介面、貼上剪貼簿內容並按下Enter鍵。

此貼上指令會下載並執行Psychedelic竊取程式。透過讓受害者手動啟動最後步驟,此攻擊行動可規避多種設計用於偵測自動下載攻擊或瀏覽器漏洞的安全工具。惡意活動源自用戶在可信網域上的自主操作,使其成為特別有效的規避策略。

利用信任:劫持合法性的戰略

選擇入侵真實商業網站是戰略性的力量倍增器。用戶天生更傾向信任熟悉的企業網域,而非陌生且名稱可疑的網站。這種固有信任使他們更容易遵從螢幕指示,即使這些指示涉及不尋常的技術步驟。

報告指出,被鎖定的烏克蘭網站均為真實營運的企業,為託管於其上的偽造Cloudflare誘餌提供了強大的可信度。此方法將常規網站瀏覽轉變為潛在的安全事件,證明即使瀏覽看似可信的線上資產,也不能放鬆警惕。

深入 Psychedelic 竊取程式

一旦安裝,Psychedelic竊取程式便開始從受感染裝置竊取資料。雖然報導時尚未有完整的技術拆解,但此類竊取程式通常針對敏感資料,例如儲存的瀏覽器憑證、加密貨幣錢包檔案,以及各種線上服務的工作階段Cookie。

此攻擊行動使用新命名的惡意軟件家族,暗示這可能是開發中的新工具,或最近加入網絡犯罪生態系統的程式。由於此前缺乏曝光,安全供應商在開發並分發防護特徵碼期間,此惡意軟件可能暫時規避基於特徵碼的偵測。

建立多層防禦

防禦此類攻擊需要多方面同步採取行動。此攻擊行動突顯了IT團隊三個關鍵防禦要務:

  1. 強化網絡資產以防初始入侵: 攻擊始於合法網站被入侵。組織必須透過嚴格補丁管理、安全編碼實踐及定期安全審計,優先保障網絡應用程式安全性,防止其線上資產被劫持並用作誘餌。

  2. 加強終端監控以偵測用戶觸發活動: ClickFix技術依賴受害者貼上並執行指令。安全團隊應配置端點偵測與回應解決方案,密切監控並警示可疑的用戶觸發活動,例如異常的PowerShell執行或命令提示字元使用——這些都是此攻擊鏈的關鍵指標。

  3. 持續用戶培訓以識別社交工程: 用戶是攻擊鏈最後且最關鍵的環節。持續的安全意識培訓至關重要,特別針對ClickFix等社交工程手段進行教育。必須教導員工質疑並拒絕要求其手動執行指令的提示,即使這些提示出現在可信網站上。

社交工程手段的持續演進,結合對可信基礎設施的利用,仍然是重大威脅。此次攻擊行動明確提醒:強韌的防禦姿態建立於強大的技術控制與充分知情的人力防線之上。

新聞來源 / Original News Source