A new malware campaign is hijacking trusted Ukrainian business websites to lure visitors into installing a previously undocumented information stealer. The attack demonstrates how threat actors are compromising legitimate infrastructure to defeat security software and user caution.

The operation, observed in late September, uses the "ClickFix" social engineering technique. Attackers first compromise legitimate business websites, ensuring the sites retain their valid SSL certificates and clean reputation. They then inject pages mimicking a standard Cloudflare security checkpoint.

When a user visits an infected site, they see the fake verification prompt. It instructs them to copy a provided command and paste it into the Windows Run dialog or Command Prompt to "verify they are human." This manual action is the attack's core trick, bypassing browser security controls by having the user execute the malicious command themselves.

The pasted command triggers a Windows Installer package that downloads and installs the "Psychedelic" stealer. This malware was not previously documented in threat intelligence. The campaign's power lies in its abuse of trust: a known domain with a padlock icon is used to trick users into performing a risky action they would normally avoid on an unknown site.

Security analysts note the attack relies purely on social engineering, not technical exploits. It uses a familiar pretext—the ubiquitous Cloudflare challenge—to exploit a universal user habit: copying and pasting instructions. This makes it effective against both trained and untrained users who let their guard down on trusted sites.

For defenders, this incident highlights a dual-front responsibility. Website operators must implement strict integrity monitoring to detect unauthorized code injection promptly. Tools and practices for continuous file integrity checking, script monitoring, and rapid response are critical to prevent their platforms from being used as attack vectors.

For security teams and employees, the primary lesson is behavioral. Training must establish that any website asking a user to copy and paste system commands is suspect, regardless of its appearance. Technical controls can supplement this awareness, such as policies that restrict or alert on the execution of msiexec.exe or command shells launched immediately after web browsing.

The "Psychedelic" stealer campaign underscores that trust is now a primary attack surface. Defending it requires vigilant website hygiene and a user population conditioned to question, not just comply with, on-screen instructions.


一場新的惡意軟件攻擊活動正劫持受信任的烏克蘭商業網站,誘騙訪客安裝一款先前未有紀錄的資訊竊取軟件。此攻擊手法顯示威脅行為者如何日益增加地侵佔合法基礎設施,以規避安全軟件及用戶警惕性。

這項於九月下旬被發現的行動,採用了「ClickFix」社交工程技術。攻擊者首先入侵合法商業網站,確保這些網站保留其有效的SSL證書及良好信譽。隨後他們注入偽裝成標準Cloudflare安全檢查站的頁面。

當用戶訪問受感染的網站時,會看到虛假的驗證提示。它指示用戶複製所提供的指令,並貼到Windows執行視窗或命令提示字元中,以「驗證你是人類」。這項手動操作正是攻擊的核心詭計,透過讓用戶自行執行惡意指令,繞過瀏覽器安全控制。

貼上的指令會觸發Windows安裝程式套件,下載並安裝名為「Psychedelic」的竊取軟件。此惡意軟件此前未有在威脅情報中紀錄。該攻擊活動的威力在於其對信任的濫用:一個帶有鎖頭圖示的已知網域名稱,被用來欺騙用戶執行他們在未知網站上通常會避免的高風險操作。

安全分析師指出,該攻擊純粹依賴社交工程,並非利用技術漏洞。它採用一個常見的藉口——無處不在的Cloudflare挑戰——利用用戶普遍的習慣:複製及貼上指令。這使得訓練有素及未經訓練的用戶,在信任的網站上放鬆警惕時都容易中招。

對於防禦者而言,此事件突顯了雙重責任。網站營運商必須實施嚴格的完整性監控,及時偵測未經授權的代碼注入。持續的檔案完整性檢查、腳本監控及快速應對的工具與實踐,對於防止其平台被用作攻擊媒介至關重要。

對於安全團隊及員工,主要教訓在於行為層面。培訓必須確立任何要求用戶複製及貼上系統指令的網站都應被視為可疑,無論其外觀如何。技術控制措施可補充這種意識,例如制定政策,限制或警報於網頁瀏覽後立即執行msiexec.exe或命令列 shell。

「Psychedelic」竊取軟件攻擊活動強調,信任現已成為主要攻擊面。防禦它需要既嚴謹的網站衛生管理,也需要用戶習慣養成質疑而非僅僅服從螢幕指示的行為模式。

新聞來源 / Original News Source