A fresh wave of cyberattacks is weaponizing trust in legitimate websites, security researchers have revealed. A ClickFix campaign has been observed compromising authentic Ukrainian business sites to inject bogus Cloudflare verification pages and lure victims into downloading a previously undocumented information stealer dubbed Psychedelic, according to a report by The Hacker News.
Rather than relying on deceptive emails or fabricated login portals, the threat actors first infiltrate real, reputable websites. Once inside, they inject malicious pages designed to mimic Cloudflare's familiar verification screen — a routine checkpoint that most internet users have learned to accept without a second thought.
The Anatomy of the Lure
The core of the attack is a textbook ClickFix tactic. When a visitor interacts with the compromised page, they are prompted to "verify" they are human. The page copies a Windows Installer command to the clipboard and instructs the visitor to paste it into their Terminal or Command Prompt. The copied text is, in fact, a malicious installation command.
The user's own hands become the delivery mechanism. Once the command is executed, the installer pulls down and deploys the Psychedelic information stealer.
Security analysts note that Psychedelic is a serious threat. It is engineered to extract a broad range of sensitive data directly from an infected machine: saved browser cookies, session tokens, login credentials stored in browsers, cryptocurrency wallet files, and personal documents. The theft of session tokens is particularly dangerous, as it allows attackers to hijack active online accounts without needing to crack a single password.
Why Compromised Sites Make This Dangerous
The use of legitimate infrastructure is the campaign's most potent advantage. Traditional phishing emails often contain tell-tale signs of fraud — suspicious sender addresses, awkwardly worded messages. Fake websites can be flagged by security software.
But an attack hosted on a real company's compromised domain bypasses many of these standard defenses. Users are far less likely to question a warning served from a domain they already trust, and security tools may whitelist the site based on its established reputation. For website administrators, this underscores a critical responsibility: protecting platform integrity is not just about safeguarding company data, but also about shielding visitors from becoming unwitting malware delivery vectors.
Defending Against ClickFix Campaigns
While the attacks observed to date have targeted Ukrainian sites, the underlying method poses a universal threat. Organizations should review and reinforce the following defensive measures:
-
User Education: The most critical defense is a vigilant user. Security awareness training must specifically address ClickFix tactics. Employees should understand that legitimate services like Cloudflare will never ask them to paste a command into a terminal to verify their identity.
-
Enhanced Endpoint Protection: Deploy and maintain advanced Endpoint Detection and Response (EDR) solutions capable of detecting and blocking suspicious command-line executions — particularly those initiated by users themselves.
-
Web Application Security: For organizations running web servers, harden Content Management Systems (CMS) and web applications. Regularly update all software, plugins, and themes, and employ Web Application Firewalls (WAF) to monitor for and block unauthorized code injections.
-
Script Execution Policies: Implement strict policies that disable or severely restrict the execution of Windows Script Host and PowerShell for standard users. This can prevent many common malware payloads from running.
-
Incident Response Planning: Ensure plans are in place to quickly isolate and clean an infected workstation, and to force password resets for any potentially compromised accounts — especially those with elevated privileges.
The ClickFix/Psychedelic campaign is a reminder that social engineering is evolving to exploit both human psychology and the inherent trust embedded in our digital infrastructure. Vigilance at every level — from the individual user to the server administrator — remains the primary line of defense.
安全研究人員揭露,一波新的網絡攻擊正將對合法網站的信任武器化。根據 The Hacker News 的一份報告指出,一個 ClickFix 攻擊行動被觀察到入侵真實的烏克蘭商業網站,注入偽造的 Cloudflare 驗證頁面,並引誘受害者下載一款名為 Psychedelic 的全新資訊竊取惡意軟件。
威脅行為者並非依賴欺詐電郵或偽造的登入門戶,而是先滲透真實且信譽良好的網站。一旦入侵成功,他們便注入惡意頁面,模仿 Cloudflare 眾所周知的驗證畫面——一個多數互聯網用戶已習慣不假思索便接受的常規檢查點。
誘餌的剖析
此次攻擊的核心是典型的 ClickFix 策略。當訪客與被入侵的頁面互動時,會收到一個「驗證你是否真人」的提示。頁面會將一個 Windows Installer 指令複製到剪貼簿,並指示訪客將其貼到終端機或命令提示字元中。實際上,被複製的文字是一段惡意的安裝指令。
用戶自己的雙手便成為了傳送機制。指令一旦執行,安裝程式便會下載並部署 Psychedelic 資訊竊取程式。
安全分析師指出, Psychedelic 是一個嚴重的威脅。它被設計用於直接從受感染的機器提取大量敏感資料:已儲存的瀏覽器 Cookie、工作階段代碼、瀏覽器中儲存的登入憑證、加密貨幣錢包文件及個人文件。工作階段代碼的竊取尤其危險,因為這使得攻擊者無需破解任何密碼即可劫持活躍的線上帳戶。
為何被入侵的網站使其危害更大
使用合法基礎設施是此攻擊行動最具威力的優勢。傳統的釣魚電郵通常帶有欺詐的跡象——可疑的寄件者地址、措辭生硬的訊息。偽造的網站可能被安全軟件標記。
但托管在真實公司被入侵網域上的攻擊,能繞過許多此類標準防禦。用戶較難質疑來自一個他們已信任網域的警告,安全工具也可能基於該網站既有的信譽將其列入白名單。對於網站管理員而言,這突顯了一項關鍵責任:保護平台完整性不僅是為了保障公司數據,更是為了保護訪客不被無意中變成惡意軟件的傳播載體。
防禦 ClickFix 攻擊行動
雖然迄今觀察到的攻擊均針對烏克蘭網站,但其底層方法構成普遍威脅。組織應審視並加強以下防禦措施:
-
用戶教育: 最關鍵的防禦是警覺的用戶。安全意識培訓必須特別針對 ClickFix 策略進行說明。員工應理解,像 Cloudflare 這類合法服務永遠不會要求他們將指令貼到終端機以驗證身份。
-
加強端點保護: 部署並維護先進的端點偵測及回應 (EDR) 解決方案,以偵測並阻止可疑的命令列執行——特別是那些由用戶自行發起的操作。
-
Web 應用程式安全: 對於營運 Web 伺服器的組織,應強化內容管理系統 (CMS) 及 Web 應用程式的安全性。定期更新所有軟件、插件及佈景主題,並採用 Web 應用程式防火牆 (WAF) 監控及阻止未經授權的代碼注入。
-
腳本執行政策: 制定嚴格的政策,停用或嚴重限制標準用戶執行 Windows Script Host 和 PowerShell。這可以阻止許多常見的惡意軟件載體運行。
-
事件回應規劃: 確保有計劃能快速隔離並清理受感染的工作站,並強制重設任何可能已被入侵帳戶的密碼——尤其是那些具有提升權限的帳戶。
ClickFix/Psychedelic 攻擊行動提醒我們,社會工程正不斷演進,利用人類心理以及嵌入在我們數碼基礎設施中的固有信任。從個別用戶到伺服器管理員,每一層級的警惕仍是首要的防線。
