Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
- ID
- 28184
- Status
- summarized
- Published
- 24 Sep 2026, 10:29 PM
- Fetched
- 25 Sep 2026, 12:40 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/hacked-ukrainian-sites-serve-fake.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 4.5
- Created
- 25 Sep 2026, 12:42 AM
- Tags
- Audience
- developersvibe_coders
What happened
Arctic Wolf Labs documented an active ClickFix campaign that injected iframes (loading fsputnik[.]com/tds/tracker[.]js) into legitimate Ukrainian business sites — a hair-treatment clinic, scale-model manufacturer, bookseller/publisher, psychological facility, tool retailer and automotive retailer. Visitors see a fake Cloudflare verification page with Ukrainian-language instructions that copies an msiexec.exe command to the clipboard and tells them to paste it into the Windows Run dialog; after a 3-second spinner the 'Done' button stays disabled for roughly 35 more seconds. The MSI payloads (elita.msi, miks.msi, astra.msi, harbor.msi, neon.msi, sova.msi, vyse.msi) are hosted on uasputnik[.]com — registered September 9, 2026 — and fetch psychedeliclove.exe from 107.175.82[.]242:9000; the resulting Psychedelic Stealer grabs Chromium browser credentials, account tokens and crypto-wallet data, sets scheduled-task persistence, and polls a C2 server.
Why it matters
The report states plainly that the 35-second delay 'does not verify that the visitor opened Windows Run, pasted the command, or installed the payload' — it is interface theatre, so any security awareness rule that treats 'I completed the CAPTCHA flow' as a trust signal is wrong. If you maintain a website (including an SME site), the compromise vector here is injected iframes on otherwise normal business pages, so a routine check for unexpected iframes and outbound requests to unfamiliar domains is the concrete action. Also note the lure borrows Cloudflare's brand: telling users 'it looked like Cloudflare' no longer distinguishes safe from malicious, and anyone who routinely copy-pastes commands from web pages into a terminal or Run dialog is the target profile.
Discussion angle
Walk through the actual lure timing live (3-second spinner, then ~35 seconds of a disabled 'Done' button) and ask: does your onboarding, support docs, or internal runbook ever tell a user to paste a command into Windows Run? If yes, that habit is what this campaign monetises — and the listed victim types (clinic, bookseller, retailer) are the same class of site most Malaysian SMEs run.