$ techbeacon▋
Phishing

Ukrainian Business Sites Hijacked to Deploy New Psychedelic Info‑Stealer via Fake Cloudflare Checks

Ukrainian Business Sites Hijacked to Deploy New Psychedelic Info‑Stealer via Fake Cloudflare Checks

Security researchers have identified an active campaign that targets legitimate Ukrainian commercial websites, inserting counterfeit Cloudflare verification pages that lure visitors into downloading a previously unknown malicious program dubbed "Psychedelic." The operation, dubbed ClickFix by analysts, replaces the normal security challenge with a fabricated version that appears to be part of Cloudflare's protection suite.

When users click through the fake verification, a hidden script silently triggers the download of the Psychedelic payload. Once installed, the stealer gathers a range of personal and financial data, including login credentials and payment information, before transmitting the harvested material to remote command‑and‑control servers. The malware’s code has not been seen in public threat repositories prior to this discovery, suggesting a novel development in the threat landscape.

The intrusion technique relies on compromising the content management systems of the victim sites, allowing attackers to embed malicious HTML and JavaScript directly into the page source. By masquerading the prompt as a routine Cloudflare check—a familiar security step for many internet users—the attackers exploit the trust users place in well‑known service providers. This social‑engineering angle increases the likelihood that unsuspecting visitors will comply, inadvertently installing the stealer.

Cyber‑security experts note that Ukraine has been a focal point for various intrusion campaigns, often tied to geopolitical tensions and financially motivated cybercrime. The use of a fake Cloudflare verification page is not entirely new, but the coupling with an undocumented information stealer marks an escalation in sophistication. The Hacker News first reported the activity, prompting security firms to issue advisories urging website operators to audit their platforms for unauthorized code injections.

Defenders recommend a multi‑layered response: immediate inspection of website files for anomalous scripts, reinforcement of access controls on content management systems, and deployment of web‑application firewalls capable of detecting and blocking counterfeit verification pages. Users are also advised to verify the authenticity of any security challenge by checking the URL for proper Cloudflare branding and to avoid downloading files prompted by unexpected pop‑ups. As researchers continue to dissect the Psychedelic malware, additional indicators of compromise are expected to emerge, aiding broader detection efforts across the region and beyond.

Threat Desk — Threat desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related