A new wave of ClickFix social engineering attacks has been observed hijacking legitimate Ukrainian business websites to distribute a previously undocumented information stealer dubbed "Psychedelic," according to a report from The Hacker News.

The campaign marks a notable evolution by using compromised authentic sites as the delivery vector, rather than the typical malicious domains. This tactic exploits the inherent user trust placed in familiar brands, making the deception far more effective and difficult to spot.

The attack chain begins when a user visits a compromised website. Instead of the expected content, they encounter a bogus Cloudflare "checking your browser" verification page. This page instructs the visitor to prove they are human by copying and executing a specific command. The lure page copies a Windows Installer (msiexec) command directly to the user's clipboard and provides simple, step-by-step prompts to paste it into a command line or Run dialog.

Once executed, this command initiates the download and installation of the Psychedelic malware. This stealer is designed to exfiltrate sensitive data, including login credentials, browser cookies, cryptocurrency wallet details, and files.

The use of legitimate sites as a distribution vector poses a significant challenge for defenses focused on blocking known malicious domains. For administrators, it underscores the critical need for robust website integrity monitoring to detect unauthorized code injections. For all users, the incident is a stark reminder to treat unsolicited instructions—especially those asking to manually execute commands—with extreme skepticism, even on reputable sites.


根據《The Hacker News》報導,研究人員發現一波新的ClickFix社交工程攻擊浪潮,利用被入侵的合法烏克蘭商業網站來散布一個名為「Psychedelic」的先前未紀錄資訊竊取程序。

此攻擊行動標誌著一個顯著演進,採用被入侵的合法網站作為分發載體,而非傳統的惡意網域。這項策略利用了使用者對熟悉品牌的固有信任,使欺騙行為更為有效且難以察覺。

攻擊鏈始於使用者訪問遭入侵網站時。使用者不會看到預期內容,而是遭遇偽造的Cloudflare「正在檢查您的瀏覽器」驗證頁面。該頁面指示訪問者透過複製並執行特定指令來證明其為人類。誘餌頁面會將Windows安裝程式(msiexec)指令複製到使用者剪貼簿,並提供簡單分步驟提示將其貼到命令列或執行對話框中。

一旦執行,此指令便會啟動Psychedelic惡意軟件的下載與安裝。這款資訊竊取程序旨在竊取敏感資料,包括登入憑證、瀏覽器cookies、加密貨幣錢包詳情及文件。

將合法網站用作分發載體,對專注於封鎖已知惡意網域的防禦措施構成重大挑戰。對系統管理員而言,這凸顯了實施強健網站完整性監控以偵測未經授權程式碼注入的關鍵必要性。對所有使用者而言,此事件是一個鮮明警示:即使是在知名網站上,也應以極度懷疑的態度看待未經請求的指令,尤其是那些要求手動執行指令的指示。

新聞來源 / Original News Source