Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » Hackers Use Fake Cloudflare Checks to Spread Psychedelic Stealer in Ukraine

Hackers Use Fake Cloudflare Checks to Spread Psychedelic Stealer in Ukraine

By:
Last updated:September 26, 2026
Human Written
  • Attackers compromised legitimate Ukrainian websites and used fake Cloudflare checks to deliver Psychedelic Stealer.

  • The malware targets browser passwords, account tokens and cryptocurrency wallets while supporting additional remote tasks.

  • Researchers also identified a separate ClickFix campaign involving RemotePanel and BoundSiphon, showing the wider use of the technique.

Hackers Use Fake Cloudflare Checks to Spread Psychedelic Stealer in Ukraine

Reports from cybersecurity specialists indicate the finding of a ClickFix campaign that targets authentic Ukrainian corporate sites. The techniques involved in this campaign consist of an imitation of Cloudflare verification websites prompting victims to install malware known as Psychedelic Stealer that infects their systems.

The campaign targets browser credentials, account tokens, and cryptocurrency wallets. Researchers also found signs that the malware can maintain access and receive further commands from its operators.

Attackers Turn Trusted Websites into Malware Traps

The campaign starts with compromised websites rather than obvious malicious pages. Researchers found several affected Ukrainian businesses across different sectors. The list includes a hair-treatment clinic, a model manufacturer and a specialist bookseller. Other affected sites include a psychological facility, a tool retailer and an automotive business.

Attackers inserted an iframe into the legitimate websites. That iframe loads JavaScript from attacker-controlled infrastructure and displays the fake verification page. The page copies a Windows Installer command into the visitor’s clipboard. It then asks the visitor to open the Windows Run dialog and paste the command.

This technique forms part of the ClickFix attack method. The approach uses fake instructions to persuade users to perform actions that trigger malware installation. The campaign uses msiexec.exe to retrieve an MSI installer.

Researchers identified several installer names, including elita.msi, miks.msi, astra.msi and harbor.msi. The attackers also registered the uasputnik[.]com domain on September 9, this year. Researchers linked that domain to the malicious infrastructure of the campaign.

The fake page copies the command before it shows the Windows Run instructions. It then displays a short loading animation before enabling the next stage of the lure. Importantly, the delay does not confirm that the victim opened Windows Run. It also does not prove that the victim pasted or executed the command.

Psychedelic Stealer Targets Passwords and Crypto Wallets

Once the victim runs the installer, the MSI package retrieves the next-stage payload. Researchers have identified the payload of malware as psychedeliclove.exe, a 64-bit executable application for Windows. The malware aims at credentials from Chromium-based browsers including Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Yandex.

The Psychedelic Stealer malware has the capability of collecting browser account tokens. Such tokens allow criminals to access specific accounts without having to go through the hassle of stealing passwords. The malware can even hunt for valuable information related to cryptocurrency in the wallets of victims.

In addition to that, the malware is also capable of scanning the applications on the user’s desktop that are related to cryptocurrency applications, such as Exodus wallet, Atomic Wallet, Electrum wallet, Bitcoin Core, Litecoin Core, etc. Besides that, the malware can obtain other data from the victimized computer as well and deliver it to the command and control (C2) system.

In addition, Psychedelic Stealer can modify browser profiles. It can extract an embedded extension archive and create a native-messaging bridge. That feature gives the malware more reach than a basic information stealer. It can connect browser components with software running on the local computer.

The malware also contacts its C2 server for additional instructions – its task system can receive EXE, COM, BAT, CMD, MSI and PowerShell payloads. Therefore, attackers could use the initial infection to introduce additional malware later. The infection does not have to end after the stealer collects passwords or wallet data.

Campaign Activity Points Strongly Toward Ukraine

Researchers discovered an exposed management panel connected to the campaign. The panel helps operators configure their web lures and monitor visitor activity. The panel recorded 557 views, 426 clicks and 79 complete events during the analysis. Those interactions came from 32 countries.

Ukraine accounted for most of the recorded activity. Researchers counted 446 views, 351 clicks and 71 complete events from the country. Other recorded countries included the United States, Poland, Germany, Canada and the Netherlands. However, the numbers measure interaction with the lure.

They do not prove that every visitor installed the malware. A page view or click alone cannot confirm a successful compromise. Researchers also found Russian-language branding and other implementation clues. They assessed that the campaign may involve Russian-speaking operators.

The researchers have not publicly attributed the operation to a named threat group. Still, Ukrainian-language instructions and compromised Ukrainian websites show a clear focus on Ukrainian users.

The campaign also shows why compromised legitimate websites create a serious problem. Visitors may trust a familiar business website and lower their guard. Attackers can then place the fake verification page inside that trusted environment. The user sees a familiar Cloudflare-style screen instead of an obviously suspicious website.

Another ClickFix Campaign Delivers More Malware

The discovery comes alongside another ClickFix campaign involving two previously undocumented .NET malware tools. Blackpoint Cyber identified the pair as RemotePanel and BoundSiphon. RemotePanel gives attackers persistent remote access to infected Windows systems. It can support PowerShell activity, file and process management, screen access and hidden virtual network computing.

This malware pretends to be a Windows Time service to remain active on infected systems. BoundSiphon focuses on information theft. It targets browser credentials, sessions, cryptocurrency wallets, password manager data, and selected documents.

The stealer also targets secrets protected by Chromium App-Bound Encryption. Researchers found that it runs mainly from memory rather than installing itself for long-term persistence. The second campaign also uses ClickFix as its starting point. Attackers persuade users to execute commands, then launch a multi-stage infection process.

ClickFix has also appeared in campaigns targeting Ukraine through other delivery methods, including the charity-themed attack described in our report on Ukraine’s defense forces hit by a charity scam delivering backdoor malware.

The chain can abuse the CMSTPLUA COM object to bypass User Account Control. It can then run an elevated PowerShell process without displaying the normal permission prompt. Afterward, the attackers can weaken Microsoft Defender protections and deploy the two malware components.

Analysis of both attacks shows the ClickFix campaign is more than simple phishing. Attackers can make use of the method at the beginning of their larger malware attacks. Nevertheless, the warning for users is simple: the Cloudflare-type verification webpage should not be asking users to copy commands into the Run section of Windows.

In addition, users should not run any commands that they do not know just to prove that they are human. Such actions can expose them to malware, with direct access to their passwords, browser sessions, and cryptocurrency wallets.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.