A newly discovered information-stealing malware, dubbed "Psychedelic," is being distributed through a sophisticated social engineering campaign that leverages hacked legitimate Ukrainian business websites. The attack, analysed by security researchers, represents a potent case study in modern phishing that shifts the execution burden onto the user.
According to a report from The Hacker News, the campaign compromises reputable Ukrainian sites and injects them with fake Cloudflare verification pages. This technique, known as "ClickFix," does not rely on technical browser vulnerabilities but on exploiting a user's learned trust in routine web procedures.
When a visitor arrives at one of the compromised sites, they are presented with a page mimicking a standard Cloudflare security check. The lure instructs the user to copy and paste a provided Windows Installer command into their system's terminal or command prompt to "verify they are human." This action, a common workaround for certain network checks, bypasses security warnings because the user is willingly initiating the process. Upon execution, the command fetches and installs the previously undocumented Psychedelic stealer.
The strategic use of legitimate, hacked Ukrainian websites is a key force multiplier for this campaign. Attackers gain immediate credibility, as the lure appears on a domain with an existing reputation, helping it evade traditional domain-based security filters. This tactic makes the fake Cloudflare page far more convincing than one hosted on a newly created, suspicious domain.
The Psychedelic malware itself is designed for information theft. While specific details of its data-harvesting capabilities are still emerging, such stealers typically target browser credentials, cryptocurrency wallets, and other sensitive local files.
Defensive Recommendations
This campaign underscores the need for a dual-focused defensive strategy targeting both infrastructure integrity and user awareness.
For Web Administrators and IT Teams: * Implement Integrity Monitoring: Deploy file integrity monitoring (FIM) on critical web servers to alert on unauthorized changes to website files, which is the initial infection vector here. * Conduct Regular Security Audits: Proactively scan for vulnerabilities in web applications and server configurations that could allow initial compromise. * Review Access Controls: Ensure server and Content Management System (CMS) access is governed by the principle of least privilege, making it harder for attackers to inject malicious code.
For End Users: * Exercise Skepticism with Execution Prompts: Users should be educated to question any website that asks them to copy and paste commands into a terminal, regardless of how legitimate the site appears. * Verify Unusual Requests: Treat any unexpected "verification" step that involves running local commands with extreme caution. Legitimate services rarely, if ever, require such actions. * Utilize Security Software: Ensure endpoint protection solutions are active and up-to-date, as they may detect the malicious payload even if the initial social engineering step is followed.
This attack is a clear reminder that phishing has evolved beyond deceptive links. Adversaries are now expertly weaponizing user habits and the trusted infrastructure of the web itself. Organizations and individuals worldwide must adapt their defenses to account for these social engineering techniques, where the user is coerced into becoming an unwitting accomplice in their own compromise.
一種新發現的資訊竊取惡意軟件「迷幻(Psychedelic)」,正透過一場精心設計的社會工程學攻擊行動散播,該行動利用已被入侵的烏克蘭合法商業網站。安全研究人員分析指出,這次攻擊是現代釣魚攻擊的一個典型案例,其特點在於將執行負擔轉移至用戶身上。
據《The Hacker News》報導,該攻擊行動入侵了具信譽的烏克蘭網站,並在其中植入偽造的 Cloudflare 驗證頁面。此技術名為「ClickFix」,並非依賴瀏覽器的技術漏洞,而是利用用戶對日常網絡操作流程的信任習慣。
當訪客瀏覽其中一個被入侵的網站時,會看到一個模仿標準 Cloudflare 安全檢查的頁面。該誘餌指示用戶複製並貼上一個提供的 Windows Installer 指令至系統的命令提示字元或終端機,以「驗證自己是人類」。這項操作通常是某些網絡檢查的常見解決方案,由於是用戶主動發起,因此能繞過安全警告。指令執行後,便會下載並安裝此前未被記錄的 Psychedelic 竊取器。
策略性地利用這些被入侵的烏克蘭合法網站,是這次攻擊行動的主要推動力。攻擊者因此立即獲得可信度,因為誘餌出現在一個已建立聲譽的網域上,有助於繞過傳統基於網域的安全過濾機制。此策略使得偽造的 Cloudflare 頁面,比起架設在新建、可疑網域上的偽頁更具說服力。
Psychedelic 惡意軟件本身專為資訊竊取而設計。雖然其數據收集能力的具體細節仍在逐步揭露中,但此類竊取器通常以瀏覽器登入憑證、加密貨幣錢包及其他敏感的本地檔案為目標。
防禦建議
這次攻擊行動突顯了同時聚焦於基礎設施完整性和用戶意識的雙重防禦策略之必要。
針對網站管理員及IT團隊: * 實施完整性監控: 在關鍵網絡伺服器上部署檔案完整性監控(FIM),以便對網站檔案的未經授權更改發出警報,這是本次攻擊的初始感染向量。 * 進行定期安全審計: 主動掃描網絡應用程式及伺服器配置中的漏洞,這些漏洞可能導致初始入侵。 * 審查存取控制: 確保伺服器及內容管理系統(CMS)的存取權限遵循最小權限原則,使攻擊者更難注入惡意代碼。
針對終端用戶: * 對執行指令提示保持質疑: 應教育用戶對任何要求他們複製指令至終端機的網站抱持懷疑態度,無論該網站看起來多麼可信。 * 核實不尋常的要求: 對任何涉及執行本地指令的意外「驗證」步驟保持極度謹慎。合法服務極少要求此類操作。 * 使用安全軟件: 確保端點防護解決方案保持啟用並更新至最新版本,因為即使用戶遵循了初始社會工程學步驟,這些軟件仍可能偵測到惡意載荷。
這次攻擊清楚提醒我們,釣魚攻擊已進化超越欺騙性連結。對手現已精於利用用戶習慣和網絡可信基礎設施本身。全球的組織和個人必須調整其防禦策略,以應對這些社會工程學技巧——在這些技巧中,用戶會被迫在不自覺的情況下成為自身資料外洩的幫兇。
