AI Weekly Malaysia

Back to items Summaries

Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

ID
28184
Status
summarized
Published
24 Sep 2026, 10:29 PM
Fetched
25 Sep 2026, 12:40 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/hacked-ukrainian-sites-serve-fake.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
4.5
Created
25 Sep 2026, 12:42 AM
Tags
Audience
developersvibe_coders

What happened

Arctic Wolf Labs documented an active ClickFix campaign that injected iframes (loading fsputnik[.]com/tds/tracker[.]js) into legitimate Ukrainian business sites — a hair-treatment clinic, scale-model manufacturer, bookseller/publisher, psychological facility, tool retailer and automotive retailer. Visitors see a fake Cloudflare verification page with Ukrainian-language instructions that copies an msiexec.exe command to the clipboard and tells them to paste it into the Windows Run dialog; after a 3-second spinner the 'Done' button stays disabled for roughly 35 more seconds. The MSI payloads (elita.msi, miks.msi, astra.msi, harbor.msi, neon.msi, sova.msi, vyse.msi) are hosted on uasputnik[.]com — registered September 9, 2026 — and fetch psychedeliclove.exe from 107.175.82[.]242:9000; the resulting Psychedelic Stealer grabs Chromium browser credentials, account tokens and crypto-wallet data, sets scheduled-task persistence, and polls a C2 server.

Why it matters

The report states plainly that the 35-second delay 'does not verify that the visitor opened Windows Run, pasted the command, or installed the payload' — it is interface theatre, so any security awareness rule that treats 'I completed the CAPTCHA flow' as a trust signal is wrong. If you maintain a website (including an SME site), the compromise vector here is injected iframes on otherwise normal business pages, so a routine check for unexpected iframes and outbound requests to unfamiliar domains is the concrete action. Also note the lure borrows Cloudflare's brand: telling users 'it looked like Cloudflare' no longer distinguishes safe from malicious, and anyone who routinely copy-pastes commands from web pages into a terminal or Run dialog is the target profile.

Discussion angle

Walk through the actual lure timing live (3-second spinner, then ~35 seconds of a disabled 'Done' button) and ask: does your onboarding, support docs, or internal runbook ever tell a user to paste a command into Windows Run? If yes, that habit is what this campaign monetises — and the listed victim types (clinic, bookseller, retailer) are the same class of site most Malaysian SMEs run.

Top