A malware campaign is weaponizing hacked Ukrainian business websites to deliver a previously unknown information stealer, exploiting a social engineering technique known as ClickFix to trick users into running malicious commands themselves.

According to an analysis reported by The Hacker News, attackers have compromised legitimate Ukrainian company websites and injected them with fake Cloudflare security verification pages. Visitors to these hijacked sites are presented with a simulated human verification step that appears routine.

The lure then employs the ClickFix method: instead of a simple checkbox, a malicious Windows Installer command is copied to the user's clipboard. The page instructs the visitor to paste this command into a Windows terminal or PowerShell window to "prove" they are human and resolve the issue. This technique leverages the common troubleshooting instinct to copy-paste solutions, turning a trusted action into a malware delivery vector.

The payload delivered is a newly documented information stealer dubbed "Psychedelic." Researchers found it is configured to exfiltrate browser data from Firefox and steal active sessions from the Telegram desktop client, indicating a focus on harvesting credentials and persistent access. Its capabilities align with the "stealer-as-a-service" model, where malware developers sell tools for stealing session cookies, passwords, and cryptocurrency wallet data on dark web forums.

The campaign highlights two critical vulnerabilities. First, it demonstrates how attackers abuse trusted infrastructure—legitimate, familiar domains—to bypass conventional security filters that block known malicious sites. A user may trust a compromised local business site more than an unknown link. Second, it marks a shift in social engineering from automated downloads to manual execution. By requiring users to actively paste and run a command, the method can evade security tools that primarily scan for malicious URLs or file-based payloads.

For organizations, this underscores the essential need for website integrity monitoring and server hardening. Keeping content management systems, plugins, and servers patched and secure is the primary defense against inadvertently hosting malware lures. For users, the key takeaway is extreme caution: any website prompting you to paste commands into a terminal window should be treated as highly suspicious, regardless of its apparent legitimacy.

The emergence of Psychedelic via this vector shows attackers continually adapting to exploit trust in digital ecosystems and user habits, making proactive website security and user awareness more critical than ever.


一場惡意軟件攻擊活動正利用遭入侵的烏克蘭商業網站,投放一種先前未被發現的信息竊取軟件。該活動利用一種名為「ClickFix」的社交工程技術,誘騙用戶自行執行惡意指令。

根據 The Hacker News 報導的分析,攻擊者已入侵了合法的烏克蘭公司網站,並注入假冒的 Cloudflare 安全驗證頁面。訪問這些被劫持網站的用戶會看到一個看似常規的模擬人類驗證步驟。

該誘餌隨後採用 ClickFix 方法:頁面不會簡單地顯示一個複選框,而是將一條惡意的 Windows Installer 指令複製到用戶的剪貼簿中。頁面指示訪問者將此指令貼上到 Windows 命令提示字元或 PowerShell 視窗中,以「證明」自己是人類並解決問題。這種技術利用了人們複製貼上解決方案的常見排錯本能,將一個受信任的動作轉變為惡意軟件的傳播載體。

投遞的有效載荷是一種被命名為「Psychedelic(迷幻)」的新型信息竊取軟件。研究人員發現,該軟件被設定為從 Firefox 瀏覽器外洩數據,並從 Telegram 桌面用戶端竊取活躍會話,顯示其專注於收割登入憑證及維持持久訪問權限。其功能符合「竊取軟件即服務」模式,即惡意軟件開發者在暗網論壇上出售用於竊取會話 Cookies、密碼及加密貨幣錢包數據的工具。

此次攻擊活動突顯了兩個關鍵漏洞。首先,它展示了攻擊者如何濫用受信任的基礎設施——合法且熟悉的網域——來繞過那些封鎖已知惡意網站的傳統安全過濾器。用戶可能比未知連結更信任一個遭入侵的本地企業網站。其次,它標誌著社交工程手法從自動下載轉向手動執行的轉變。透過要求用戶主動貼上並執行指令,該方法能夠規避主要掃描惡意 URL 或基於文件的有效載荷的安全工具。

對組織而言,這突顯了網站完整性監控及伺服器強化的基本必要性。確保內容管理系統、外掛程式及伺服器保持最新修補及安全,是防止無意間託管惡意軟件誘餌的首要防禦措施。對用戶而言,關鍵要點是保持高度警惕:任何要求你將指令貼上到命令視窗的網站,無論其表面看似多麼合法,都應被視為高度可疑。

透過此載體出現的 Psychedelic 軟件表明,攻擊者不斷適應,利用人們對數字生態系統及用戶習慣的信任進行攻擊,這使得主動的網站安全及用戶意識比以往更為重要。

新聞來源 / Original News Source