A sophisticated attack campaign is weaponizing legitimate, compromised business websites to deploy a newly identified information stealer dubbed "Psychedelic." Security researchers disclosed the operation on 26 September, revealing a method that abuses trust in familiar web domains and security protocols.

The attack begins with the compromise of authentic Ukrainian business websites. Instead of normal content, visitors are greeted with a convincing replica of a Cloudflare "Checking your browser" verification page. This tactic hijacks a routine web experience to establish instant credibility. When a user attempts to interact with the fake checkpoint, the page covertly copies a malicious Windows Installer command to their clipboard, accompanied by instructions to paste and run it in a system dialog like the Run box.

This "ClickFix" method is highly effective because it turns the victim into an active participant. By requiring the manual paste-and-execute step, the attack evades standard security defenses such as browser sandboxing, download warnings, and email filtering that would typically block a malicious file transfer. The user, believing they are merely completing a standard security check, inadvertently triggers the infection.

Upon execution, the command fetches and installs the Psychedelic stealer. While the malware is newly documented and its full toolset is still being analyzed, such infostealers are typically designed to harvest sensitive data. Primary targets almost certainly include login credentials, cryptocurrency wallet files, session cookies, and confidential documents. Its emergence highlights the persistent evolution within the malware-as-a-service economy.

Defending against this threat requires a layered approach for security teams and website administrators. Organizations must implement continuous integrity monitoring and web application firewalls for their external sites to quickly detect unauthorized content injection. Endpoint detection and response (EDR) tools should be tuned to flag suspicious activity chains where a command is pasted and executed following a browser session. Crucially, user awareness training must be updated to teach staff that legitimate security services, like those from Cloudflare, never instruct users to manually copy and paste commands into system prompts, even on trusted websites.

The campaign poses a significant risk for organizations with a public web presence, demonstrating how compromised trusted domains can be leveraged to bypass user skepticism and technical safeguards. Proactive monitoring of both web properties and endpoint activity is now essential to counter this evolving social engineering vector.


一項精密的攻擊行動正利用遭入侵的合法商業網站,部署一種新發現、被命名為「Psychedelic」的資訊竊取程序。安全研究人員於9月26日披露此行動,揭示了一種濫用熟悉網域及安全協議信任機制的攻擊方法。

攻擊始於入侵真實的烏克蘭商業網站。訪客不會看到正常內容,而是會見到一個極具說服力的仿製Cloudflare「檢查瀏覽器」驗證頁面。此策略劫持了常規的網絡體驗,以建立即時可信度。當使用者試圖與這個偽造的檢查點互動時,該頁面會暗中將惡意的Windows安裝指令複製到其剪貼簿,並附上說明,指導使用者將其貼上並在系統對話框(如「執行」對話框)中運行。

這種稱為「ClickFix」的方法效果顯著,因為它將受害者轉變為主動參與者。透過要求手動貼上與執行的步驟,攻擊得以規避標準安全防禦機制,例如瀏覽器沙箱、下載警告及通常會阻止惡意檔案傳輸的郵件過濾。使用者自以為僅是在完成一項標準安全檢查,卻無意中觸發了感染。

指令執行後,會下載並安裝Psychedelic竊取程序。儘管此惡意軟件屬新近被記錄,其完整工具組仍在分析中,但此類資訊竊取程序通常旨在擷取敏感資料。首要目標幾乎肯定包括登入憑證、加密貨幣錢包檔案、工作階段Cookie及機密文件。它的出現突顯了「惡意軟件即服務」經濟中持續存在的演進。

防範此威脅需要安全團隊和網站管理員採取多層次的方法。組織必須為其外部網站實施持續性完整性監控及網絡應用程式防火牆,以快速偵測未經授權的內容注入。端點偵測與回應工具應經調整,以標記可疑活動鏈,例如在網絡工作階段後貼上並執行指令的行為。至關重要的是,使用者認知培訓必須更新,以教導員工:即使是在受信任的網站上,像Cloudflare這類合法安全服務絕不會指示使用者手動將指令複製並貼上到系統提示中。

此行動對具有公開網絡形象的組織構成重大風險,展示了遭入侵的受信任網域如何被用來繞過使用者懷疑及技術保障措施。現時,對網絡資產和端點活動的主動監控,已成為對抗這種不斷演化的社會工程攻擊向量的必要措施。

新聞來源 / Original News Source