Cybersecurity researchers have identified an active ClickFix campaign that is compromising legitimate Ukrainian business websites to distribute a previously undocumented information stealing malware known as Psychedelic Stealer. The campaign uses fake Cloudflare verification pages to trick visitors into executing malicious commands that install the malware on Windows systems. According to Arctic Wolf Labs, the attackers have injected compromised websites with fraudulent verification screens designed to appear similar to legitimate security checks, using social engineering techniques to convince users to copy and execute harmful commands. The activity highlights the continued use of trusted website infrastructure and familiar security branding to distribute malware and steal sensitive information.
Researchers said the compromised websites include businesses from different sectors, such as a hair treatment clinic, a scale model manufacturer, a specialist bookseller and publisher, a psychological facility, a tool retailer, and an automotive retailer. The affected websites contained injected iframe elements that loaded attacker controlled JavaScript from an external domain. When visitors interacted with the fake Cloudflare page, the malicious script copied a Windows Installer command to the clipboard and instructed users to paste it into the Windows Run dialog. The command used msiexec.exe to download a Windows MSI installer responsible for delivering the malware. The fake verification page reportedly displayed Ukrainian language instructions and included delays designed to guide users through the process without actually verifying whether the command had been executed.
The ClickFix chain downloaded MSI installers, including files named elita.msi, miks.msi, astra.msi, harbor.msi, neon.msi, sova.msi, and vyse.msi, from attacker controlled infrastructure. The MSI installer then retrieved the next stage payload, identified as psychedeliclove.exe, which researchers classified as Psychedelic Stealer. The malware is designed to collect sensitive information from infected systems, including credentials stored in Chromium based browsers such as Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Vivaldi, and Yandex. It can also collect account tokens, cryptocurrency wallet information from browser extensions and desktop applications, and detailed system information. Researchers found that the malware communicates with a command and control server to transmit stolen information and receive additional instructions.
According to Arctic Wolf, Psychedelic Stealer includes capabilities that extend beyond one time data collection. The malware can terminate selected browser processes, modify browser profiles, extract extension archives, and establish a native messaging bridge that allows browser components to communicate with local system processes. Researchers stated that these functions indicate a broader effort to maintain control over infected systems rather than simply collecting information during initial execution. The malware can also request additional tasks from its command infrastructure, allowing operators to execute further payloads, including EXE, COM, BAT, CMD, MSI, and PowerShell files. An exposed lure management panel associated with the campaign was also identified, providing operators with visibility into visitor interactions with the fake verification pages.
The campaign infrastructure reportedly recorded hundreds of interactions across multiple countries, with Ukraine accounting for the majority of observed activity. Researchers said Ukrainian language instructions, compromised Ukrainian websites, and visitor data from the management panel indicate that Ukrainian users were a primary focus of the campaign. While the identity of the operators remains unconfirmed, Arctic Wolf suggested that Russian language elements and implementation details may indicate a possible connection to Russian speaking operators. Researchers have also observed other ClickFix campaigns delivering different malware families, including RemotePanel and BoundSiphon, which combine remote access capabilities with credential and cryptocurrency theft features. These developments reflect a growing trend of modular malware operations that separate persistent access functions from data theft components, allowing attackers to adjust infrastructure and payloads while maintaining access to compromised systems. Organizations are advised to strengthen website security monitoring, avoid executing unknown commands from browser prompts, and maintain updated security controls to reduce exposure to similar threats.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.