$ techbeacon▋
Phishing

Ukrainian Business Sites Weaponized to Deploy Fake Cloudflare CAPTCHA and Credential‑Stealing Malware

Ukrainian Business Sites Weaponized to Deploy Fake Cloudflare CAPTCHA and Credential‑Stealing Malware

Cybercriminals have taken control of several Ukrainian business websites and are using them to serve a counterfeit Cloudflare CAPTCHA that silently installs the malware known as Psychedelic Stealer. The malicious code harvests browser passwords, cryptocurrency wallet keys and other sensitive data from visitors who interact with the bogus challenge.

The attack chain relies on hidden iframe injection. When a user accesses an infected page, an invisible frame loads a replica of Cloudflare's verification widget. The page appears legitimate, prompting the visitor to solve a CAPTCHA. Once the challenge is completed, the script triggers the download and execution of Psychedelic Stealer without the user’s knowledge, allowing the threat actors to capture credentials stored in the browser and any connected crypto extensions.

Psychedelic Stealer is a modular information‑stealing tool that has been observed in previous campaigns targeting financial information and cryptocurrency assets. Its capabilities include extracting saved passwords, session cookies, and private keys from popular browsers and wallet extensions. By bundling the payload with a familiar security prompt, the operators increase the likelihood that victims will unwittingly grant the malware the permissions it needs.

The compromise of Ukrainian commercial sites is particularly concerning given the region’s active cryptocurrency community and the reliance on online services for business operations. Security analysts warn that even a brief visit to a compromised domain could expose users to credential theft, potentially leading to unauthorized transactions or account takeovers. While the full scale of the campaign remains under investigation, the use of trusted local domains amplifies the risk of widespread infection.

This technique reflects a broader trend in cybercrime where attackers co‑opt well‑known security services to lend credibility to their payloads. Similar tactics have been seen in prior campaigns that spoofed SSL certificate warnings or used legitimate content delivery networks to bypass security filters. By embedding malicious iframes within reputable sites, threat actors exploit the trust users place in familiar brands, making detection by casual users more difficult.

Researchers from the security community have disclosed the findings and are urging both site owners and internet users to take precautionary steps. Web administrators should audit their pages for unauthorized iframe elements, verify the integrity of third‑party scripts, and employ strict Content Security Policies. End users are advised to confirm the authenticity of any CAPTCHA challenge—especially when it appears on sites that do not normally require Cloudflare protection—and to keep browsers and security software up to date. Monitoring for unusual login activity and employing hardware wallets for crypto assets can further reduce the impact of potential credential theft.

Vikas Thakur — Vikas covers DDoS attacks, botnet infrastructure, and network-layer threats. Hands-on experience with mitigation and traffic analysis, covers IoT botnets and infra-level attacks.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related