Attackers are hijacking legitimate Ukrainian business websites to host fake Cloudflare security checks, tricking visitors into installing a new information-stealing malware. Security researchers report that the campaign exploits user trust in both the compromised domains and Cloudflare's verification system, using a "ClickFix" technique to turn the victim into the final step of the attack chain.
The lure begins when a user visits a compromised site. Instead of the expected content, they encounter a page mimicking Cloudflare's standard "Verify you are human" interface—a common and generally trusted sight on the internet. As part of the fake verification process, the page automatically copies a Windows Installer command to the user's clipboard. It then displays instructions urging the visitor to paste the command into the Windows Run dialog and execute it manually.
This deliberate user action is the crux of the ClickFix method. It bypasses many automated security controls that block unauthorized downloads or script executions. Running the pasted command (which uses msiexec.exe) fetches and installs the payload: a .NET-based stealer malware dubbed "Psychedelic." Once active, the malware creates a scheduled task to maintain persistence on the infected system and proceeds to harvest sensitive data.
The campaign's power lies in its dual exploitation of trust. First, the attackers leverage the credibility of a legitimate business domain to lower the visitor's guard. Second, they use the universally recognized interface of a Cloudflare security check to provide a plausible reason for the suspicious instruction. This combination makes the social engineering potent and difficult for users to question.
This incident exposes a critical blind spot in many organizational security strategies. While significant resources are often dedicated to securing endpoints and email gateways, the integrity of public-facing websites can be overlooked. Compromised web assets can instantly transform into trusted malware distribution platforms, bypassing traditional perimeter defenses.
For defenders, the takeaway is a need for strategic reallocation. Prioritizing integrity monitoring for all web properties—checking for unauthorized content injection, unexpected code changes, and fake verification pages—is essential. Equally crucial is updating user awareness programs to specifically train employees to recognize and reject ClickFix-style ploys. The core lesson is that a legitimate website instruction to manually paste and run a command is always malicious. The "Psychedelic" stealer itself is less significant than the sophisticated, replicable delivery method used to deploy it.
攻擊者正劫持合法的烏克蘭商業網站,託管偽造的 Cloudflare 安全檢查頁面,欺騙訪客安裝新型資料竊取惡意軟件。安全研究人員報告指,該攻擊活動利用用戶對受入侵網域及 Cloudflare 驗證系統的信任,採用「ClickFix」技術,將受害者變為攻擊鏈的最後一環。
誘騙始於用戶訪問受入侵的網站。訪客不會看到預期內容,而是遇到模仿 Cloudflare 標準「驗證您是人類」介面的頁面——這是互聯網上常見且普遍被信任的界面。作為偽造驗證流程的一部分,該頁面會自動將 Windows Installer 命令複製到用戶的剪貼簿中,隨後顯示指示,敦促訪客將命令貼上到 Windows「執行」對話方框中並手動執行。
這種刻意要求用戶採取行動的設計,正是 ClickFix 方法的核心。它繞過了許多用於阻止未授權下載或腳本執行的自動化安全控制。運行貼上的命令(使用 msiexec.exe)會下載並安裝有效負載:一款名為「Psychedelic」的基於 .NET 架構的竊取惡意軟件。一旦啟動,惡意軟件會建立排定任務以在受感染系統中維持持久性,並開始收集敏感資料。
此次攻擊活動的威力在於其對信任的雙重利用。首先,攻擊者利用合法商業網域的信譽降低訪客的戒心。其次,他們使用普遍認可的 Cloudflare 安全檢查介面,為可疑指令提供看似合理的理由。這種組合使得社交工程攻擊極具說服力,難以讓用戶產生質疑。
此事件暴露了許多組織安全策略中的一個關鍵盲點。儘管大量資源通常用於保護端點和電子郵件閘道,但面向公眾的網站完整性可能被忽視。受入侵的網頁資產可瞬間轉變為受信任的惡意軟件分發平台,繞過傳統的周邊防禦。
對防禦者而言,關鍵教訓是需要進行策略性資源重新配置。優先對所有網絡資產進行完整性監控至關重要——檢查是否存在未經授權的內容注入、異常代碼變更及偽造的驗證頁面。同樣重要的是更新用戶意識培訓計劃,專門訓練員工識別並拒絕 ClickFix 式的欺騙手段。核心啟示在於:任何合法網站要求手動貼上並執行命令的指示,均屬惡意行為。「Psychedelic」竊取軟件本身的意義,遠不如用於分發它的複雜、可複製的傳播方法重要。
