A new wave of attacks is compromising legitimate Ukrainian business websites to trick visitors into installing a previously unseen information stealer called Psychedelic. Researchers have identified the campaign as leveraging a deceptive social engineering technique known as "ClickFix" to bypass traditional security and user suspicion.

The attackers first gain control of trusted company domains in Ukraine. Once a site is compromised, they inject fake pages that closely mimic Cloudflare's security verification screens. This abuse of a known, reputable infrastructure is a key component of the attack's effectiveness, forcing malicious activity to originate from what appears to be a safe source.

Anatomy of the ClickFix Trap

The core of the deception is a "ClickFix" pattern designed to feel like a routine security check. When a user visits the hijacked site, they are presented with a fake CAPTCHA or browser verification prompt. The page then:

  1. Silently copies a malicious command to the user's clipboard.
  2. Instructs the user to open a terminal or command prompt.
  3. Prompts them to paste and execute the clipboard contents to complete the "verification."

This technique is highly effective because it manipulates users into performing the malicious action themselves. Pasting a command into a terminal often feels less risky than downloading and running an unknown executable, significantly lowering a victim's defenses. The executed command downloads and installs the Psychedelic stealer.

The Psychedelic Stealer's Objectives

Once deployed, the Psychedelic malware is engineered to steal high-value data for credential theft and financial fraud. Its primary targets include:

  • Browser Credentials: Harvesting saved usernames and passwords from web browsers.
  • Session Cookies: Hijacking active login sessions to bypass authentication entirely.
  • Cryptocurrency Wallets: Stealing data files from local wallets for direct asset theft.
Defense-in-Depth Strategies

Mitigating this threat requires action from both website defenders and end-users.

Website Owners and Administrators: * Prioritize Integrity Monitoring: Implement systems to detect unauthorized changes to files and database content, particularly on public-facing pages. * Maintain Rigorous Patching: Keep all CMS platforms, plugins, and server software updated to eliminate common attack vectors. * Analyze Traffic Logs: Monitor for unusual activity that could indicate compromise, such as unexpected script injections.

End-Users and Employees: * Reject Manual Execution Prompts: Treat any website instruction to copy and run a command in your terminal as a definitive red flag. Legitimate verification processes do not require this. * Verify Through Official Channels: If prompted by a supposed service like Cloudflare, access the site via a different network or directly contact the service through official support to confirm system status. * Never Run Unverified Commands: Do not paste and execute commands from a browser without thorough understanding and independent verification.

This campaign marks an evolution in social engineering, shifting from simple phishing links to manipulating users within the trusted context of a familiar website. It underscores the critical need for enhanced website integrity monitoring and user education on advanced technical red flags.


一波新攻擊正入侵烏克蘭合法商業網站,誘騙訪客安裝名為「迷幻」(Psychedelic)的前所未見竊密軟件。研究人員已識別該攻擊行動利用一種名為「ClickFix」的欺騙性社會工程技術,以繞過傳統安全措施及用戶戒心。

攻擊者首先取得烏克蘭受信任企業網域的控制權。一旦網站被入侵,他們便注入偽造頁面,高度模仿Cloudflare的安全驗證畫面。這種濫用知名可靠基礎設施的手法,是攻擊成效的關鍵要素,使惡意活動看似來自安全來源。

ClickFix陷阱剖析

欺騙的核心是旨在模擬例行安全檢查的「ClickFix」模式。當用戶造訪被劫持的網站時,會看到偽造的CAPTCHA或瀏覽器驗證提示。隨後頁面會:

  1. 靜默複製惡意指令至用戶剪貼簿。
  2. 指示用戶開啟終端機或命令提示字元。
  3. 提示他們貼上並執行剪貼簿內容以完成「驗證」。

此手法效果顯著,因為它操縱用戶自行執行惡意操作。將指令貼入終端機往往比下載並執行未知執行檔風險更低,大幅降低受害者防禦心理。所執行的指令會下載並安裝「迷幻」竊密軟件。

「迷幻」竊密軟件目標

一旦部署,「迷幻」惡意軟件專門竊取高價值數據用於憑證盜竊及金融詐騙。其主要目標包括:

  • 瀏覽器憑證: 收割網頁瀏覽器儲存的用戶名稱與密碼。
  • 工作階段Cookies: 劫持有效登入工作階段以完全繞過驗證機制。
  • 加密貨幣錢包: 竊取本地錢包數據檔案以直接盜取資產。
縱深防禦策略

緩解此威脅需要網站防護方及終端用戶共同採取行動。

網站所有者及管理員: * 優先實施完整性監控: 部署偵測未經授權檔案及資料庫內容變更的系統,特別針對公開頁面。 * 維持嚴格補丁管理: 確保所有內容管理系統平台、外掛程式及伺服器軟件保持更新,以消除常見攻擊向量。 * 分析流量日誌: 監測可能顯示入侵跡象的異常活動,例如意外的指令碼注入。

終端用戶及員工: * 拒絕手動執行提示: 將任何要求複製指令至終端機執行的網站指示視為明確警告訊號。合法驗證流程不會要求此操作。 * 透過官方渠道核實: 若收到來自Cloudflare等服務的提示,請透過不同網路造訪網站,或直接透過官方支援聯繫服務商確認系統狀態。 * 切勿執行未經驗證指令: 在未充分理解及獨立驗證前,切勿從瀏覽器貼上並執行指令。

此次攻擊行動標誌著社會工程學的演進,從簡單釣魚連結轉向在熟悉網站的可信情境中操縱用戶。這凸顯了加強網站完整性監控及提升用戶對高階技術警告訊號認知的迫切需求。

新聞來源 / Original News Source