A newly observed cyber campaign is weaponizing legitimate Ukrainian business websites to trap visitors with a sophisticated ClickFix ruse, ultimately delivering a previously undocumented information-stealer named "Psychedelic."
Researchers have identified that attackers are compromising the infrastructure of authentic Ukrainian companies. When users navigate to these hijacked sites, they are not greeted with the usual content. Instead, they are presented with a meticulously crafted fake Cloudflare verification page, a tactic designed to exploit the inherent trust placed in both the familiar brand and the compromised domain itself.
This fake checkpoint operates by hijacking the user's workflow. The malicious page automatically copies a Windows Installer command to the clipboard and displays instructions prompting the visitor to open a "Run" dialog or PowerShell terminal. By pasting and executing the copied command—a step victims believe is a routine security measure—they inadvertently download and install the Psychedelic malware payload.
The emergence of this stealer highlights an active and evolving threat. Its specific data exfiltration capabilities are still being analyzed, but like similar malware, its primary targets are likely to be credentials, session cookies, cryptocurrency wallet files, and other sensitive data residing on the target system.
This incident marks a significant escalation in ClickFix tactics. While previous campaigns often used cloned sites or malvertising, directly compromising trusted business portals represents a dangerous advancement. It fundamentally undermines a core safety assumption of the web: that visiting a known, legitimate website is inherently secure.
Defending against this vector requires a combination of technical controls and user education. Organizations should deploy file integrity monitoring on their web assets to quickly detect unauthorized changes. On endpoints, security tools must be tuned to recognize and block the anomalous pattern of a user manually pasting and executing installer commands.
Crucially, user training must evolve to address this specific social engineering trick. Users should be explicitly taught that legitimate services like Cloudflare will never ask them to manually copy and execute commands via their system's command line. Any webpage making such a request should be treated as malicious and reported immediately.
The campaign demonstrates how attackers are now layering exploitation of technical vulnerabilities with potent social engineering, leveraging systemic trust to bypass traditional security perimeters.
近期觀察到的一場網絡攻擊活動,正利用合法的烏克蘭企業網站,透過精密的ClickFix誘騙手段設下陷阱,最終投放一種名為「Psychedelic」的全新未記錄資訊竊取惡意軟件。
研究人員確認攻擊者入侵了正規烏克蘭企業的基礎設施。當用戶造訪這些被挾持的網站時,並非看到正常內容,而是被呈現一個精心偽造的Cloudflare驗證頁面——此策略旨在利用人們對該知名品牌及被入侵網域本身的固有信任。
這個偽造檢查點通過劫持用戶的工作流程運作。惡意頁面會自動將一條Windows Installer指令複製到剪貼簿,並顯示指示,要求訪問者開啟「執行」對話框或PowerShell終端機。通過貼上並執行複製的指令(受害者認為這是例行安全措施),他們便無意中下載並安裝了Psychedelic惡意軟件的有效負載。
這種竊取工具的出現凸顯了一個活躍且不斷演進的威脅。其具體的資料外洩能力仍在分析中,但如同類似惡意軟件,其主要目標很可能是目標系統上的認證資料、會話Cookie、加密貨幣錢包文件及其他敏感資料。
此事件標誌著ClickFix戰術的重大升級。雖然先前的攻擊活動常使用克隆網站或惡意廣告,但直接入侵受信任的商業門戶則代表了危險的進展。這根本性地破壞了網絡的一項核心安全假設:訪問已知的合法網站本質上是安全的。
防禦此類攻擊向量需要結合技術控制與用戶教育。組織應在網絡資產上部署檔案完整性監控,以快速偵測未授權的變更。在端點設備上,安全工具必須調整為能識別並阻止用戶手動貼上並執行安裝指令的異常模式。
至關重要的是,用戶培訓必須演進以應對這種特定的社會工程學伎倆。應明確教導用戶,像Cloudflare這樣的合法服務永遠不會要求他們透過系統的命令行手動複製並執行指令。任何提出此類要求的網頁都應被視為惡意並立即舉報。
該攻擊活動顯示,攻擊者正將技術漏洞利用與強大的社會工程學手段層層結合,利用體系性的信任來繞過傳統的安全邊界。
