
Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
Arctic Wolf Labs has uncovered a ClickFix campaign that abuses compromised Ukrainian business websites to show fake Cloudflare verification pages and deliver a new information stealer called Psychedelic.
An active ClickFix campaign is compromising legitimate Ukrainian business websites to serve fake Cloudflare verification pages and trick visitors into downloading a new information stealer called Psychedelic. Arctic Wolf Labs described the activity in a report shared with The Hacker News.
The lure
When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and tells them to paste it into the Windows Run dialog. An "msiexec.exe" command then fetches an MSI installer that delivers the malware. The analysed sample, "elita.msi", sits on "uasputnik.com", a domain registered on September 9, 2026.
The page imitates a Cloudflare verification screen with Ukrainian-language instructions. The clipboard operation runs before the Run prompt appears: after a three-second spinner the dialog shows up and the "Done" button stays disabled for about 35 more seconds, a delay that Arctic Wolf says only paces the interface.
What Psychedelic collects
The installer pulls the next stage, "psychedeliclove.exe", from 107.175.82.242:9000. The 64-bit executable steals credentials from Chromium-based browsers such as Google Chrome, Microsoft Edge, Brave, Opera and Yandex, harvests account tokens and scans for cryptocurrency wallets including MetaMask, Trust Wallet, OKX Wallet, Exodus and Electrum.
It also captures host information, sets up scheduled-task persistence, drops an extension archive into browser profiles and installs a native-messaging bridge. Through the "/api/v1/agent/tasks?hwid=%s" endpoint it fetches more work and can run EXE, COM, BAT, CMD, MSI and PowerShell payloads.
Targets and operators
Among the compromised sites are a hair-treatment clinic, a scale-model manufacturer, a bookseller and publisher, a psychological facility, a tool retailer and an automotive retailer. Each carried an injected iframe that loaded attacker-controlled JavaScript from "fsputnik.com/tds/tracker.js". Arctic Wolf also found an exposed lure panel named РУБЛЁВКА TDS on the uasputnik.com domain, separate from the implant's C2 at 193.178.159.128:8080.
That dashboard polls visitor records every two seconds; at the time of analysis it had logged 557 views, 426 clicks and 79 complete events across 32 countries. Ukraine accounted for 446 views, 351 clicks and 71 complete events. Russian-language branding suggests Russian operators, while the Ukrainian instructions point to a campaign aimed at Ukrainian users.
RemotePanel and BoundSiphon
Blackpoint Cyber separately described two undocumented .NET components delivered through ClickFix: RemotePanel, a persistent remote access platform posing as the Windows Time service, and BoundSiphon, a memory-resident stealer aimed at Chromium, Firefox and password manager data. RemotePanel resolves its C2 through a BNB Smart Chain contract, so operators can rotate infrastructure without redeploying. Blackpoint said the activity is not attributed to a known group, though artifacts point to a Russian-speaking development environment.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.