A social engineering campaign is targeting visitors to compromised Ukrainian business websites, distributing a previously undocumented information stealer called "Psychedelic" through fake Cloudflare verification pages. The operation leverages the "ClickFix" technique to manipulate users into executing malicious code themselves.
The attack chain begins when threat actors compromise legitimate Ukrainian websites and inject bogus Cloudflare "challenge" pages designed to mimic standard bot verification protocols. When a visitor interacts with the page, a script silently copies a Windows Installer command to their clipboard. The fake verification page then instructs the victim to paste and execute this command in their terminal or Run dialog to "complete verification."
This approach represents a calculated evasion strategy. By placing the final execution step in human hands—requiring manual pasting and running of the command—the attack circumvents many automated security tools that detect direct drive-by downloads. The technique exploits the trust users naturally place in legitimate business domains, significantly reducing suspicion.
Once executed, the command delivers the "Psychedelic" stealer payload. Researchers describe this malware as a new addition to the expanding "stealer-as-a-service" ecosystem, where criminal operators lease tools designed to exfiltrate sensitive data including credentials, session cookies, and local files from compromised systems.
The campaign highlights two critical defensive priorities. Website administrators must implement robust integrity monitoring and patch management to prevent the initial compromise of trusted web assets. End-user awareness remains equally essential: employees should be trained to recognize and reject any instruction to manually copy and execute commands from a browser. No legitimate verification process requires such an action.
The emergence of Psychedelic through ClickFix lures underscores a broader trend in the threat landscape. Attackers continue to refine social engineering methods that exploit human psychology, often with greater effectiveness than technical exploits alone. As automated defenses improve, securing the human layer becomes increasingly vital.
一項社會工程攻擊活動正針對訪問遭入侵烏克蘭商業網站的訪客,透過偽造的Cloudflare驗證頁面散播一種名為「Psychedelic」的新型資訊竊取軟件。此行動利用「ClickFix」技術操控用戶自行執行惡意代碼。
攻擊鏈始於威脅行為者入侵合法烏克蘭網站,並注入旨在模仿標準機器人驗證協議的偽造Cloudflare「挑戰」頁面。當訪客與頁面互動時,腳本會靜默將Windows安裝程序命令複製至其剪貼簿。偽造驗證頁面隨後指示受害者將此命令貼上並執行於其終端機或執行對話框,以「完成驗證」。
此方法代表一種經過計算的迴避策略。透過將最終執行步驟交由人手——要求人手貼上並執行命令——該攻擊繞過了許多偵測直接偷渡下載的自動化安全工具。此技術利用了用戶對合法商業網域自然產生的信任,大幅降低其警覺性。
命令一旦執行,便會投遞「Psychedelic」竊密軟件攻擊載荷。研究人員形容此惡意軟件為不斷擴張的「竊密軟件即服務」生態系統中的新成員,犯罪營運者在此租賃旨在從受感染系統外洩敏感數據的工具,包括憑證、工作階段Cookie及本地檔案。
該攻擊活動突顯了兩項關鍵防禦優先事項。網站管理員必須實施強大的完整性監控及補丁管理,以防止受信任網頁資產遭初步入侵。終端用戶意識同樣至關重要:應訓練員工識別並拒絕任何指示其人手複製及執行來自瀏覽器命令的指示。任何合法驗證過程均無需此類操作。
透過ClickFix誘餌出現的Psychedelic軟件,突顯了威脅環境中更廣泛的趨勢。攻擊者持續改良利用人類心理的社會工程方法,其效果往往優於純技術漏洞利用。隨著自動化防禦改進,確保人體層的安全變得日益重要。
