A new wave of attacks is hijacking legitimate Ukrainian business websites to deploy a previously undocumented information stealer named "Psychedelic." The campaign exploits the "ClickFix" social engineering technique, tricking visitors into executing malicious commands themselves to bypass traditional download warnings.
Security researchers have documented an active attack where compromised local business sites present visitors with counterfeit Cloudflare verification pages. The lure leverages the trust users place in both the original website and the ubiquitous Cloudflare service. Instead of a direct download, the page guides the user through a manual "verification" step.
The core trick is the ClickFix method. An embedded script copies a malicious Windows Installer command to the visitor's clipboard, instructing them to paste and execute it within the Windows Run dialog or Command Prompt. This user-initiated action is designed to bypass security software that flags suspicious downloads, making the infection more likely to succeed.
Once executed, the command silently installs the Psychedelic stealer. While a full technical analysis is pending, such malware typically harvests browser credentials, cryptocurrency wallet files, session cookies, and other sensitive system data for theft or resale.
The incident highlights a critical shift in web-based threats. A compromised website is no longer just a data breach risk; it becomes an active malware distribution platform leveraging its own trusted visitor base. This places a significant burden on web administrators to monitor site integrity and implement robust security controls.
For defenders, the campaign underscores that modern social engineering often targets human trust rather than software vulnerabilities. Effective protection requires a layered approach: organizations must harden their web infrastructure against initial compromise, while users must be trained to distrust any prompt—even on familiar sites—that asks them to manually execute system commands. The ClickFix method proves that security awareness must extend to questioning instructions encountered in seemingly legitimate contexts.
一波新攻擊浪潮正劫持合法的烏克蘭商業網站,以部署一款名為「迷幻(Psychedelic)」的新型未記錄信息竊取軟件。該攻擊利用「ClickFix」社會工程技術,欺騙訪客自行執行惡意命令,從而繞過傳統下載警告。
安全研究人員已記錄到一起活躍攻擊事件:被入侵的本地商業網站向訪客展示偽造的Cloudflare驗證頁面。該誘餌利用了用戶對原始網站及無處不在的Cloudflare服務的信任。頁面並非直接下載文件,而是引導用戶手動完成「驗證」步驟。
核心詐術在於ClickFix方法。嵌入式腳本將惡意Windows Installer命令複製到訪客剪貼簿,指示他們在Windows執行對話框或命令提示字元中貼上並執行該命令。這種用戶主動執行的操作旨在規避會標記可疑下載的安全軟件,從而提高感染成功率。
命令一經執行,便會靜默安裝迷幻偷竊軟件。儘管完整技術分析尚待完成,但此類惡意軟件通常會竊取瀏覽器憑證、加密貨幣錢包文件、會話Cookie及其他敏感系統數據,用於盜竊或轉售。
此事件突顯了網絡威脅的重大轉變。被入侵的網站已不僅是數據洩露風險;它成為主動分發惡意軟件的平台,利用其自身受信任的訪客基礎。這對網站管理員構成重大負擔,必須監控網站完整性並實施強健的安全控制。
對於防禦者而言,此攻擊行動突顯了現代社會工程往往針對人類信任而非軟件漏洞。有效的防護需要層次化方法:組織必須加固其網絡基礎設施以防範初始入侵,而用戶則需接受訓練,不信任任何提示——即使在熟悉的網站上——要求手動執行系統命令的請求。ClickFix方法證明,安全意識必須延伸至質疑看似合法情境中遇到的指令。
