Ukrainian Websites Serve Fake Cloudflare Checks That Deliver Psychedelic Stealer

Abstract Ethereum staking and validator infrastructure security illustration

Compromised Ukrainian websites are being used to present fake Cloudflare verification pages that direct visitors through a ClickFix sequence and ultimately install an information-stealing program called Psychedelic Stealer, according to Arctic Wolf research. The campaign combines a trusted visual pattern with instructions that cause the victim to execute the attack.

Fake verification leads to command execution

A visitor to an affected site is shown a verification prompt designed to resemble a legitimate anti-bot check. Instead of completing a normal browser challenge, the user is instructed to open a system dialog, paste clipboard content and run it. That action starts a staged delivery chain outside the browser’s ordinary security boundary.

The reported stealer targets information that can support follow-on compromise, including credentials and browser data. The use of legitimate but compromised websites complicates simple reputation filtering because the initial domain may previously have been trusted.

Defenses must address the instruction pattern

Web administrators should investigate unexpected script changes, third-party injection and new redirects. Endpoint teams can monitor unusual command interpreters launched immediately after browser activity, while user guidance should make clear that a genuine web verification process does not require pasting commands into an operating-system tool.

Organizations can connect these controls with SectechMedia’s Cyber-Physical Security coverage. Detection should preserve the originating URL, browser process, clipboard-driven command and subsequent network activity so responders can identify both the compromised site and any affected endpoint.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *