A new ClickFix campaign is targeting users through compromised Ukrainian websites, deploying a previously undocumented information stealer dubbed "Psychedelic."
According to The Hacker News, attackers have taken over legitimate Ukrainian business sites and replaced their content with fraudulent pages mimicking Cloudflare's browser verification system. The deceptive pages are designed to look authentic enough to fool unsuspecting visitors.
The attack uses a social engineering technique known as ClickFix. When victims land on the fake verification page, a malicious command is silently copied to their clipboard. The page then prompts the user to paste this command into a Windows terminal or Run dialog under the pretense of proving they are human.
This approach forces the victim to actively participate in their own infection. By having the user execute the command themselves, the attack can circumvent certain automated security warnings that might otherwise flag suspicious activity. Once executed, the command reportedly retrieves and installs the Psychedelic stealer.
Two elements make this campaign particularly effective. First, the attack originates from legitimate, compromised domains—helping it evade both user suspicion and automated security filters that block known-malicious URLs. Second, the impersonation of Cloudflare, a widely recognized brand, adds a veneer of legitimacy to the deceptive request.
The incident serves as a reminder that compromised websites can pose risks even to cautious users. Organizations should implement integrity monitoring to detect unauthorized changes to their web properties. Users, meanwhile, should remain skeptical of any site that asks them to execute commands manually—regardless of how trustworthy the source appears.
一項新的 ClickFix 攻擊行動正透過遭入侵的烏克蘭網站針對使用者,部署一種名為「Psychedelic」、先前未被記錄的信息竊取惡意軟件。
據《The Hacker News》報導,攻擊者已接管合法的烏克蘭商業網站,並以其內容替換為模仿 Cloudflare 瀏覽器驗證系統的欺詐頁面。這些欺騙性頁面旨在看起來足夠逼真,以誤導毫無戒心的訪問者。
此攻擊使用一種稱為 ClickFix 的社會工程學技術。當受害者登陸偽造的驗證頁面時,一個惡意指令會被悄悄複製到其剪貼簿中。隨後,該頁面會提示用戶將此指令貼上到 Windows 命令提示字元或執行對話框中,假稱是為了「證明他們是人類」。
此方法迫使受害者主動參與自身的感染過程。透過讓用戶親自執行指令,此攻擊可以繞過某些可能標記可疑活動的自動安全警告。據報,指令一旦執行,便會檢索並安裝 Psychedelic 竊取器。
兩個因素使此次攻擊行動特別有效。首先,攻擊源自合法但遭入侵的網域——有助於規避用戶的懷疑以及封鎖已知惡意網址的自動化安全過濾器。其次,冒充廣為人知的 Cloudflare 品牌,為其欺騙性要求披上了合法性的外衣。
此事件提醒人們,即使是謹慎的用戶,也可能因遭入侵的網站而面臨風險。機構應實施完整性監控,以偵測其網絡資產的未經授權變更。與此同時,用戶應對任何要求手動執行指令的網站保持懷疑態度——無論該來源看起來多麼可信。
