A new campaign hijacks legitimate Ukrainian business websites to trick visitors into installing a previously undocumented information stealer dubbed "Psychedelic." By embedding fake Cloudflare verification pages on compromised domains, attackers exploit user trust and bypass conventional security filters.
The attack, reported by The Hacker News, begins with the compromise of real Ukrainian business websites. Once in control, attackers inject a script that presents visitors with a fake Cloudflare security challenge designed to mimic a routine human verification step.
Instead of a simple checkbox, the page instructs users to manually execute a malicious command. A Windows Installer command is copied to the victim's clipboard, accompanied by step-by-step guidance to paste and run it in the Windows Run dialog or command prompt. This deliberate user action, known as the ClickFix technique, is intended to evade automated security tools that typically scan for system-initiated downloads.
Executing the command downloads and runs the "Psychedelic" stealer. Researchers confirm this is the first documented instance of this malware. While full analysis is ongoing, early findings indicate it targets browser session tokens, cookies, credentials, and potentially cryptocurrency wallet files—suggesting active development by threat actors.
The campaign's effectiveness hinges on abuse of trust. By hosting the lure on a legitimate, compromised domain, attackers significantly improve their odds. Users are far less wary of a prompt from a known business website, and security products relying on domain reputation may not flag the activity.
This incident underscores a broader shift in modern attacks, where social engineering co-opts trusted infrastructure, targeting human psychology and administrative hygiene rather than exploiting software vulnerabilities.
Defensive Recommendations
To counter this threat vector, organizations should prioritize:
- Website Integrity Monitoring: Deploy tools to continuously scan for unauthorized changes to web content and scripts, triggering immediate alerts for modifications.
- User Education: Train users to distrust unexpected prompts for command-line actions, even from familiar sites. Legitimate services like Cloudflare never require manual clipboard execution.
- Infrastructure Hardening: Maintain rigorous patch management for web servers and CMS platforms, and enforce strict, logged access controls to prevent initial compromise.
- Endpoint Protection: Utilize advanced EDR solutions capable of detecting and blocking suspicious command executions and malware payloads.
The emergence of the Psychedelic stealer, delivered via trusted but compromised channels, highlights the need for layered defenses combining technical controls with vigilant user awareness.
一項新的攻擊行動劫持合法的烏克蘭商業網站,誘騙訪客安裝名為「Psychedelic」的新型資訊竊取惡意軟件。攻擊者通過在被入侵的域名上嵌入偽造的Cloudflare驗證頁面,利用用戶信任並繞過傳統安全過濾機制。
據《The Hacker News》報導,攻擊始於入侵真實的烏克蘭商業網站。攻擊者取得控制權後,注入腳本向訪客展示偽造的Cloudflare安全驗證頁面,模仿常規的人類驗證步驟。
頁面並非要求用戶勾選簡單的核取方塊,而是指示用戶手動執行惡意指令。Windows Installer指令被複製到受害者的剪貼簿,並附有逐步指導,引導用戶在Windows「執行」對話框或命令提示字元中貼上並運行。這種需要用戶主動操作的攻擊手法稱為ClickFix技術,旨在規避通常掃描系統主動下載行為的自動化安全工具。
執行該指令會下載並運行「Psychedelic」竊取器。研究人員確認,這是該惡意軟件首次被記錄在案。儘管完整分析仍在進行中,早期發現表明其目標包括瀏覽器會話代碼、Cookie、憑證,以及可能的加密貨幣錢包檔案,意味著攻擊者正積極開發此工具。
該攻擊行動的有效性在於濫用信任機制。通過將誘餌託管在合法的被入侵域名上,攻擊者顯著提高了成功率。用戶對來自知名商業網站的提示警惕性較低,而依賴域名信譽的安全產品可能不會將此類活動標記為威脅。
此事件突顯了現代攻擊模式的轉變——社會工程學手段濫用受信任的基礎設施,針對的是人類心理與管理疏漏,而非單純的軟件漏洞。
關鍵防禦措施
為應對此威脅,機構應優先採取以下措施:
- 網站完整性監控:部署工具持續掃描網頁內容與腳本的未授權變更,並對任何修改立即觸發警報。
- 用戶教育:訓練用戶對不期然的命令行操作提示保持警惕,即使來自熟悉網站亦然。合法服務如Cloudflare永不會要求手動剪貼簿操作。
- 基礎設施加固:嚴格管理網頁伺服器與內容管理系統的補丁,並實施嚴謹且有記錄的存取控制以防範初始入侵。
- 端點保護:採用能偵測並阻止可疑指令執行及惡意軟件載荷的進階端點偵測與回應方案。
「Psychedelic」竊取器透過受信任但被入侵的渠道出現,凸顯了結合技術控制措施與用戶警覺意識的多層次防禦之必要性。
