A sophisticated attack campaign is hijacking legitimate Ukrainian business websites to trick visitors into installing a newly discovered information-stealing malware. The operation exploits the "ClickFix" social engineering technique, using trusted corporate domains as a lure to deploy a stealer named "Psychedelic."

Security researchers, as reported by The Hacker News, found that attackers have compromised genuine Ukrainian corporate websites. On these sites, they inject fake Cloudflare security verification pages designed to mimic routine bot-check prompts—a common web element users are conditioned to trust.

The attack's effectiveness relies on a clever deception. When a user interacts with the fake verification page, the site automatically copies a specific command to the user's clipboard. The page then instructs the visitor to paste this command into the Windows "Run" dialog or a command prompt to "complete the check." This manual execution is the core of the ClickFix technique, bypassing traditional automated download protections.

The pasted command triggers msiexec.exe to fetch and run a malicious installer from a remote server. This installer delivers the "Psychedelic" stealer. By requiring the user to initiate the process, the attack evades many browser-based security tools that would block or sandbox an automatically downloaded file.

This marks the first documented use of the Psychedelic stealer. Its capabilities include harvesting saved passwords, browser session cookies, and cryptocurrency wallet files from infected machines. The campaign signifies a notable evolution in ClickFix tactics, moving from generic phishing pages to weaponizing compromised, high-trust infrastructure.

The primary danger is the subversion of user vigilance. A security prompt on the website of a known, legitimate company is far more likely to be obeyed than one on an unfamiliar domain. This strategy effectively neutralizes the basic security practice of verifying a website's authenticity through its URL.

For defenders, the incident underscores a necessary dual-layered response. Web administrators must implement file integrity monitoring to detect unauthorized changes and ensure all underlying access vulnerabilities are patched to prevent the initial compromise.

From the end-user perspective, the guidance is unambiguous: never paste commands copied from a webpage into system dialogs or terminals, no matter how credible the source appears. Users should be trained to treat unexpected verification requests with skepticism and to seek confirmation through separate, trusted channels.

This campaign demonstrates that compromised legitimate sites represent a potent vector for malware delivery, effectively inverting standard trust models. As threat actors refine such social engineering ploys, defense requires a combination of robust technical controls and an educated, cautious user base.


一場精密的攻擊行動正劫持合法的烏克蘭企業網站,誘騙訪客安裝新發現的資訊竊取惡意軟件。此行動利用「ClickFix」社會工程技術,以可信的企業域名為誘餌,部署名為「Psychedelic」的竊取工具。

據《The Hacker News》報導,安全研究人員發現攻擊者已入侵真實的烏克蘭企業網站。他們在這些網站上注入偽造的 Cloudflare 安全驗證頁面,模仿常規的機器人檢查提示——這是用戶習慣信任的常見網頁元素。

攻擊的有效性依賴巧妙的欺騙手法。當用戶與偽造的驗證頁面互動時,網站會自動將特定命令複製到用戶的剪貼簿。隨後,頁面會指示訪客將此命令貼上到 Windows「執行」對話框或命令提示字元,以「完成檢查」。這種手動執行正是 ClickFix 技術的核心,能繞過傳統的自動下載保護機制。

貼上的命令會觸發 msiexec.exe 從遠端伺服器獲取並執行惡意安裝程式。此安裝程式會投遞「Psychedelic」竊取工具。透過要求用戶主動觸發此過程,攻擊能規避許多會封鎖或隔離自動下載檔案的瀏覽器安全工具。

這標誌著 Psychedelic 竊取工具的首次被記錄使用。其能力包括從受感染機器中收集已儲存的密碼、瀏覽器會話 Cookie 和加密貨幣錢包檔案。此行動顯示 ClickFix 策術的重大演進,從通用釣魚頁面轉向利用被入侵的高信任基礎設施作為攻擊武器。

主要危險在於顛倒了用戶的警覺性。知名合法公司網站上的安全提示,比陌生域名上的提示更可能被遵從。此策略有效地消解了通過網址驗證網站真實性這一基本安全實踐的作用。

對於防禦者而言,此事件強調了採取雙層應對措施的必要性。網站管理員必須實施檔案完整性監控以偵測未授權變更,並確保所有底層存取漏洞均已修補,以防止最初的入侵。

從終端用戶的角度,指引非常明確:永遠不要將從網頁複製的命令貼上到系統對話框或終端機,無論該來源看起來多麼可信。用戶應接受培訓,對意外的驗證請求保持懷疑態度,並通過獨立的可信渠道尋求確認。

這次行動顯示,被入侵的合法網站是惡意軟件投遞的有效載體,實際上顛覆了標準的信任模型。隨著威脅行為者改進此類社會工程策略,防禦需要結合強健的技術控制與一個受過教育、謹慎的用戶群。

新聞來源 / Original News Source