A new ClickFix campaign is leveraging compromised Ukrainian business websites to distribute a previously undocumented information stealer dubbed "Psychedelic." The attack chain hijacks visitor trust by injecting fake Cloudflare security checks directly into legitimate domains.
When a user lands on an infected site, the malicious prompt automatically copies a Windows Installer command to their clipboard. The page then instructs the victim to paste and execute this command in a terminal or Run dialog to supposedly complete a "human verification" step.
This technique is a potent evolution in social engineering, designed to circumvent automated defenses. By forcing the user to become the final actor in the infection chain, the attack bypasses traditional safeguards like browser warnings against drive-by downloads or endpoint security that monitors for suspicious file executions.
The use of compromised legitimate websites is central to the attack's effectiveness. Users are inherently conditioned to trust familiar domains, making a malicious prompt on such a site far more credible than a phishing link from an unknown sender. Threat actors are effectively weaponizing the trust that organizations have built with their audiences.
The payload delivered through this ClickFix lure is the "Psychedelic" stealer. Information stealers are designed to exfiltrate sensitive data from compromised machines, including login credentials, session cookies, cryptocurrency wallets, and other personal or corporate secrets. The emergence of a new variant signals active development to evade existing detection signatures.
For IT administrators and security teams, the incident underscores the critical need for continuous integrity monitoring of all public-facing web assets. Website compromise must be recognized not just as an availability issue, but as a direct vector for attacking an organization's own users and partners.
For individuals, the primary defense is informed skepticism. The ClickFix method relies entirely on user compliance. Security awareness training must emphasize a core principle: legitimate services will never instruct users to manually copy and execute a command found on a webpage. If faced with an unexpected verification prompt, the safest action is to close the tab and access the service directly via a known, bookmarked URL.
This campaign highlights a broader trend toward attacks that manipulate human behavior and exploit trust in familiar brands, creating threats that are difficult to counter with technology alone. As analysis of the Psychedelic stealer's full capabilities continues, this case serves as a valuable exercise for testing web security protocols and user education programs.
一場新的 ClickFix 攻擊活動正利用被入侵的烏克蘭商業網站,分發一種名為「Psychedelic」的全新資訊竊取器。此攻擊鏈透過將偽造的 Cloudflare 安全檢查直接注入合法網域,以劫持訪客的信任。
當用戶造訪受感染的網站時,惡意提示會自動將一條 Windows Installer 指令複製到其剪貼簿。隨後,頁面會指示受害者貼上並在終端機或執行對話框中執行此指令,以聲稱完成「人類驗證」步驟。
這項技術是社會工程學上的一個強大演進,旨在繞過自動化防禦系統。通過強迫用戶成為感染鏈中的最終執行者,攻擊繞過了傳統的安全措施,例如瀏覽器對隨意下載的警告,或監控可疑檔案執行的端點防護。
使用被入侵的合法網站是攻擊有效性的核心。用戶天生傾向於信任熟悉的網域,使得此類網站上的惡意提示比來自未知發送者的釣魚連結更為可信。威脅行為者正有效地武器化組織與受眾之間建立的信任。
透過此 ClickFix 誘餌傳遞的載荷就是「Psychedelic」竊取器。資訊竊取器旨在從受感染的機器中滲出敏感數據,包括登入憑證、工作階段 cookie、加密貨幣錢包以及其他個人或企業機密。一個新變種的出現表明其正積極開發以規避現有的偵測特徵簽章。
對於 IT 管理員和安全團隊而言,此事件凸顯了持續監控所有面向公眾的網絡資產完整性的關鍵必要性。網站被入侵必須被視為不僅是可用性問題,更是攻擊組織自身用戶與合作夥伴的直接途徑。
對於個人而言,主要的防禦是具備知情的懷疑態度。ClickFix 方法完全依賴用戶的順從。安全意識培訓必須強調一項核心原則:合法服務永遠不會指示用戶手動複製並執行網頁上發現的指令。若遇到意外的驗證提示,最安全的行動是關閉該分頁,並透過已知、已加入書籤的 URL 直接存取服務。
此攻擊活動凸顯了一項更廣泛的趨勢:攻擊愈發傾向於操縱人類行為並利用對熟悉品牌的信任,創造出僅靠技術難以應對的威脅。隨著對「Psychedelic」竊取器完整能力的分析持續進行,此案例成為測試網絡安全協議和用戶教育計劃的寶貴演練。
